Updated pdns-recursor package fixes security vulnerability:
An issue has been found in PowerDNS Recursor where the ACL applied to the
internal web server via webserver-allow-from is not properly enforced,
allowing a remote attacker to send HTTP queries to the internal web server,
bypassing the restriction (CVE-2020-14196).
In the default configuration the API webserver is not enabled. Only
installations using a non-default value for webserver and webserver-address are affected.
- https://bugs.mageia.org/show_bug.cgi?id=26887
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-04.html
- https://doc.powerdns.com/recursor/changelog/4.1.html#change-4.1.17
- https://www.cve.org/CVERecord?id=CVE-2020-14196
- 7/core/pdns-recursor-4.1.17-1.mga7
Get the latest Linux and open source security news straight to your inbox.