{"id":"CVE-2016-7069","details":"An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT record that has to be removed before forwarding the response to the initial client. On a 32-bit system, the pointer arithmetic used when parsing the received response to remove that record might trigger an undefined behavior leading to a crash.","modified":"2026-08-07T15:18:32.281320Z","published":"2018-09-11T13:29:00.840Z","related":["SUSE-SU-2023:2760-1","SUSE-SU-2023:2760-2","SUSE-SU-2023:2777-1","openSUSE-SU-2024:12731-1"],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100509"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7069"},{"type":"FIX","url":"https://dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2017-01.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powerdns/pdns","events":[{"introduced":"0"},{"last_affected":"7b8c947ee7adc34ac512cebd066fb2bebf146647"}],"database_specific":{"cpe":"cpe:2.3:a:powerdns:dnsdist:*:*:x86:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.2.0"}],"source":"CPE_RANGE"}}],"versions":["dnsdist-1.2.0","rec-4.1.0-alpha1","dnsdist-1.1.0","dnsdist-1.1.0-beta2","dnsdist-1.1.0-beta1","rec-4.0.2","rec-4.0.1","auth-4.0.1","rec-4.0.0","auth-4.0.0","auth-4.0.0-rc1","auth-4.0.0-rc2","rec-4.0.0-rc1","rec-4.0.0-beta1","auth-4.0.0-beta1","auth-4.0.0-alpha3","rec-4.0.0-alpha3","dnsdist-1.0.0","dnsdist-1.0.0-beta1","rec-4.0.0-alpha2","auth-4.0.0-alpha2","dnsdist-1.0.0-alpha2","auth-4.0.0-alpha1","rec-4.0.0-alpha1","dnsdist-1.0.0-alpha1","auth-3.4.0","auth-3.4.0-rc2","rec-3.6.0","auth-3.4.0-rc1","rec-3.5","rec-3.5-rc5","rec-3.5-rc4","rec-3.5-rc3","rec-3.5-rc1","auth-3.2-rc4","auth-3.2-rc3","auth-3.2-rc2","auth-3.2-rc1","auth-3.1-rc3","auth-3.1-rc2","auth-3.1-rc1","rec-3.3.1","rec-3.1.4","rec-3.0.1","rec-3-0-1","rec-3.0","rec-3-0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7069.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}