Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Mageia 7: MGASA-2020-0286 Critical: pdns-recursor Remote Access Risk

mageia
Calendar Grey July 7, 2020
Dist Mageia Esm H88
Mageia 2020-0290 upgrades httpd to address vulnerability enabling external exploitation through local network.
Updated pdns-recursor package fixes security vulnerability: An issue has been found in PowerDNS Recursor where the ACL applied to the internal web server via webserver-allow-from ...

Summary

Updated pdns-recursor package fixes security vulnerability:
An issue has been found in PowerDNS Recursor where the ACL applied to the internal web server via webserver-allow-from is not properly enforced, allowing a remote attacker to send HTTP queries to the internal web server, bypassing the restriction (CVE-2020-14196).
In the default configuration the API webserver is not enabled. Only installations using a non-default value for webserver and webserver-address are affected.

References

- https://bugs.mageia.org/show_bug.cgi?id=26887

- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-04.html

- https://doc.powerdns.com/recursor/changelog/4.1.html#change-4.1.17

- https://www.cve.org/CVERecord?id=CVE-2020-14196

Resolution

SRPMS

- 7/core/pdns-recursor-4.1.17-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 07 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0286.html
Type: security
CVE: CVE-2020-14196

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here