Security restrictions bypass in PowerDNS Recursor - CVE-2019-3807

 

Security restrictions bypass in PowerDNS Recursor - CVE-2019-3807

Published: February 1, 2019


Vulnerability identifier: #VU17348
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3807
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated. A remote attacker can bypass DNSSEC validation.


Affected software

PowerDNS Recursor
Arch Linux
Fedora
Opensuse
pdns-recursor (Alpine package)
pdns-recursor

How to mitigate CVE-2019-3807

Update to version 4.1.9.

PowerDNS Recursor - update to 4.1.9
pdns-recursor (Alpine package) - update to 4.1.9-r0
pdns-recursor - addressed in versions 4.1.9-1.el7, 4.1.9-1.fc28, 4.1.9-1.fc29

External References

Related Security Bulletins