ArchLinux: 201412-9: powerdns-recursor: denial of service
Summary
PowerDNS, while acting as a caching nameserver, can be negatively impacted by sending queries for specially configured, hard to resolve domain names. This is the same issue as the ones found in bind (ASA-201412-7) and unbound (ASA-201412-8).
Resolution
Upgrade to 3.6.2-1.
# pacman -Syu "powerdns-recursor>=3.6.2-1"
The problem has been fixed upstream in version 3.6.2.
References
https://doc.powerdns.com/md/security/powerdns-advisory-2014-02/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8601
Workaround
Only clients in allow-from are able to trigger the degraded service, so this should be limited to your user base.