An issue has been found in the parsing of authoritative answers in PowerDNS Recursor, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. This issue has been assigned CVE-2017-15120.
When the PowerDNS Recursor is run inside a supervisor like supervisord or systemd, it will be automatically restarted, limiting the impact to somewhat degraded service.
PowerDNS Recursor from 4.0.0 up to and including 4.0.7 are affected.
For those unable to upgrade to a new version, a minimal patch is available
We would like to thank Toshifumi Sakaguchi for finding and subsequently reporting this issue.