MGASA-2020-0393 - Updated pdns-recursor package fixes a security vulnerability

Publication date: 24 Oct 2020
URL: https://advisories.mageia.org/MGASA-2020-0393.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-25829

An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5,
and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a
given name to be updated to the Bogus DNSSEC validation state, instead of
their actual DNSSEC Secure state, via a DNS ANY query. This results in a
denial of service for installation that always validate (dnssec=validate),
and for clients requesting validation when on-demand validation is enabled
(dnssec=process). (CVE-2020-25829)

References:
- https://bugs.mageia.org/show_bug.cgi?id=27400
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html
- https://doc.powerdns.com/recursor/changelog/4.1.html#change-4.1.18
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25829

SRPMS:
- 7/core/pdns-recursor-4.1.18-1.mga7

Mageia 2020-0393: pdns-recursor security update

An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5

Summary

An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process). (CVE-2020-25829)

References

- https://bugs.mageia.org/show_bug.cgi?id=27400

- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html

- https://doc.powerdns.com/recursor/changelog/4.1.html#change-4.1.18

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25829

Resolution

MGASA-2020-0393 - Updated pdns-recursor package fixes a security vulnerability

SRPMS

- 7/core/pdns-recursor-4.1.18-1.mga7

Severity
Publication date: 24 Oct 2020
URL: https://advisories.mageia.org/MGASA-2020-0393.html
Type: security
CVE: CVE-2020-25829

Related News