Improper input validation in PowerDNS Authoritative and PowerDNS Recursor - CVE-2018-14626

 

Improper input validation in PowerDNS Authoritative and PowerDNS Recursor - CVE-2018-14626

Published: November 19, 2018


Vulnerability identifier: #VU15961
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14626
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to DNSSEC validating clients consider the answer to be bogus until it expires from the packet cache. A remote attacker can craft a DNS query, cause an answer without DNSSEC records to be inserted into the packet cache and be returned to clients asking for DNSSEC records, thus hiding the presence of DNSSEC signatures for a specific qname and qtype.


Affected software

PowerDNS Authoritative
PowerDNS Recursor
Arch Linux
Fedora
Opensuse
Ubuntu
pdns (Alpine package)
pdns-recursor (Alpine package)
pdns-tools (Ubuntu package)
pdns-server (Ubuntu package)
pdns-recursor (Ubuntu package)
pdns
pdns-recursor

How to mitigate CVE-2018-14626

The vulnerability has been fixed in the versions 4.1.5.

PowerDNS Authoritative - update to 4.1.5
PowerDNS Recursor - update to 4.1.5
pdns (Alpine package) - addressed in versions 4.0.6-r0, 4.1.5-r0
pdns-recursor (Alpine package) - addressed in versions 4.0.9-r0, 4.1.8-r0
pdns-tools (Ubuntu package) - update to Ubuntu Pro
pdns-server (Ubuntu package) - update to Ubuntu Pro
pdns-recursor (Ubuntu package) - update to Ubuntu Pro
pdns - addressed in versions 4.0.6-2.el7, 4.1.5-1.fc27, 4.1.5-1.fc28, 4.1.5-1.fc29
pdns-recursor - addressed in versions 4.1.7-1.el7, 4.1.7-1.fc28, 4.1.7-1.fc29, 4.1.8-1.el7, 4.1.8-1.fc28, 4.1.8-1.fc29

External References

Related Security Bulletins