Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 6, MGASA-2019-0122 Moderate: Pdns Denial Of Service Issue

mageia
Calendar Grey March 29, 2019
Dist Mageia Esm H88
MGASA-2019-0122 - Updated pdns packages fix security vulnerability Publication date: 29 Mar 2019 URL
Updated pdns packages fix security vulnerability: An issue has been found in PowerDNS Authoritative Server when the HTTP remote backend is used in RESTful mode (without post=1 set...

Summary

Updated pdns packages fix security vulnerability:
An issue has been found in PowerDNS Authoritative Server when the HTTP remote backend is used in RESTful mode (without post=1 set), allowing a remote user to cause the HTTP backend to connect to an attacker-specified host instead of the configured one, via a crafted DNS query. This can be used to cause a denial of service by preventing the remote backend from getting a response, content spoofing if the attacker can time its own query so that subsequent queries will use an attacker-controlled HTTP server instead of the configured one, and possibly information disclosure if the Authoritative Server has access to internal servers (CVE-2019-3871).

References

- https://bugs.mageia.org/show_bug.cgi?id=24531

- https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-03.html

- https://www.cve.org/CVERecord?id=CVE-2019-3871

Resolution

SRPMS

- 6/core/pdns-4.1.7-1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 29 Mar 2019
URL: https://advisories.mageia.org/MGASA-2019-0122.html
Type: security
CVE: CVE-2019-3871

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here