{"id":"UBUNTU-CVE-2016-6173","details":"NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.","modified":"2025-10-24T04:45:50Z","published":"2017-02-09T15:59:00Z","upstream":["CVE-2016-6173"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2016-6173"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2016/07/06/4"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2016-6173"}],"affected":[{"package":{"name":"nsd","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/nsd@4.1.7-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.1.2-1","4.1.6-1","4.1.7-1"],"ecosystem_specific":{"binaries":[{"binary_name":"nsd","binary_version":"4.1.7-1"},{"binary_name":"nsd3","binary_version":"4.1.7-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-6173.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"negligible"}]}