Mageia 2020-0393: pdns-recursor security update
Summary
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5,
and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a
given name to be updated to the Bogus DNSSEC validation state, instead of
their actual DNSSEC Secure state, via a DNS ANY query. This results in a
denial of service for installation that always validate (dnssec=validate),
and for clients requesting validation when on-demand validation is enabled
(dnssec=process). (CVE-2020-25829)
References
- https://bugs.mageia.org/show_bug.cgi?id=27400
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html
- https://doc.powerdns.com/recursor/changelog/4.1.html#change-4.1.18
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25829
Resolution
MGASA-2020-0393 - Updated pdns-recursor package fixes a security vulnerability
SRPMS
- 7/core/pdns-recursor-4.1.18-1.mga7