CVE-2016-6173
CVE-2016-6173 is a high-severity vulnerability in Nlnetlabs Nsd with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-399.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 7.8
- EPSS exploit prediction: 3% (87th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-399
- Affected product: Nlnetlabs Nsd
- Published:
- Last modified:
Description
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
Frequently asked questions
- What is CVE-2016-6173?
- NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
- How severe is CVE-2016-6173?
- CVE-2016-6173 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2016-6173 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (87th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2016-6173?
- CVE-2016-6173 affects Nlnetlabs Nsd. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2016-6173?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2016-6173 published?
- CVE-2016-6173 was published on 2017-02-09 and last updated on 2026-06-17.
References
- http://www.nlnetlabs.nl/svn/nsd/tags/NSD_4_1_11_REL/doc/RELNOTES
- http://www.openwall.com/lists/oss-security/2016/07/06/3
- http://www.openwall.com/lists/oss-security/2016/07/06/4
- http://www.securityfocus.com/bid/91678
- https://github.com/sischkg/xfer-limit/blob/master/README.md
- https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015058.html
- https://open.nlnetlabs.nl/pipermail/nsd-users/2016-August/002342.html
- https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=790
Affected products (1)
- cpe:2.3:a:nlnetlabs:nsd:*:*:*:*:*:*:*:*
More vulnerabilities in Nlnetlabs Nsd
- CVE-2026-18664 — Critical (CVSS 9.1): When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP…
- CVE-2026-12244 — High (CVSS 8.8): If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS…
- CVE-2026-12246 — High (CVSS 8.1): NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the…
- CVE-2026-19538 — High (CVSS 7.5): The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed…
- CVE-2026-19401 — High (CVSS 7.5): Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted…
- CVE-2026-18916 — High (CVSS 7.5): Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously…
All CVEs affecting Nlnetlabs Nsd →
Other CWE-399 (Resource Management Errors) vulnerabilities
- CVE-2015-8104 — Critical (CVSS 10.0): The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a…
- CVE-2015-0339 — Critical (CVSS 10.0): Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before…
- CVE-2015-0335 — Critical (CVSS 10.0): Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before…
- CVE-2015-0333 — Critical (CVSS 10.0): Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before…
- CVE-2014-4121 — Critical (CVSS 10.0): Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized…
- CVE-2014-0560 — Critical (CVSS 10.0): Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS…
Browse all CWE-399 (Resource Management Errors) vulnerabilities →