Security restrictions bypass in PowerDNS Recursor - CVE-2019-3807

 

Security restrictions bypass in PowerDNS Recursor - CVE-2019-3807

Published: February 1, 2019


Vulnerability identifier: #VU17348
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-3807
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: PowerDNS.COM B.V.
Affected software:
PowerDNS Recursor

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated. A remote attacker can bypass DNSSEC validation.


How to mitigate CVE-2019-3807

Update to version 4.1.9.

Sources