Designate mDNS DoS through incorrect handling of large RecordSets
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Nov 26, 2024
Description
Published by the National Vulnerability Database
Aug 31, 2017
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Nov 21, 2024
Last updated
Nov 26, 2024
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
References