Input validation error in PowerDNS - CVE-2019-3871
Published: April 8, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing DNS requests in RESTful mode in the HTTP Connector of the Remote backend. A remote attacker can send a specially crafted DNS request to the affected server and perform denial of service (DoS) attack.
Affected software
Arch Linux
Fedora
SUSE Linux
Opensuse
pdns (Alpine package)
pdns (Debian package)
pdns
How to mitigate CVE-2019-3871
pdns (Alpine package) - addressed in versions 4.0.7-r0, 4.1.7-r0
pdns (Debian package) - update to 4.0.3-1+deb9u4
pdns - addressed in versions 4.1.7-1.el7, 4.1.7-1.fc28, 4.1.7-1.fc29, 4.1.7-1.fc30
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00022.html
- http://www.openwall.com/lists/oss-security/2019/03/18/4
- http://www.securityfocus.com/bid/107491
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3871
- https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-03.html
- https://lists.debian.org/debian-lts-announce/2019/03/msg00039.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GWUHF6MRSQ3YO7UUISGLV7MXCAGBW2VD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ROFI6OTWF4GKONNSNEDUCW6LVSSEBZNF/
- https://seclists.org/bugtraq/2019/Apr/8
- https://www.debian.org/security/2019/dsa-4424
Related Security Bulletins
- Denial of service in PowerDNS Authoritative Server
- Arch Linux update for powerdns
- OpenSUSE Linux update for pdns
- OpenSUSE Linux update for pdns
- Debian update for pdns
- Input validation error in pdns (Alpine package)
- Fedora 28 update for pdns
- Fedora 29 update for pdns
- Fedora 30 update for pdns
- Fedora EPEL 7 update for pdns