Input validation error in PowerDNS - CVE-2016-7073
Published: September 11, 2018 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check of the TSIG time and fudge values was found in AXFRRetriever, leading to a possible replay attack.
Affected software
Arch Linux
Fedora
Cisco Secure Access Control
pdns (Alpine package)
pdns-recursor (Alpine package)
pdns
pdns-recursor
How to mitigate CVE-2016-7073
pdns (Alpine package) - update to 4.0.3-r0
pdns-recursor (Alpine package) - update to 4.0.4-r0
pdns - addressed in versions 3.4.11-1.el7, 4.0.3-1.fc24, 4.0.3-1.fc25
pdns-recursor - addressed in versions 3.7.4-1.el6, 3.7.4-1.el7, 4.0.4-1.fc24, 4.0.4-1.fc25
External References
Related Security Bulletins
- Input validation error in PowerDNS
- Input validation error in pdns (Alpine package)
- Input validation error in pdns-recursor (Alpine package)
- Arch Linux update for powerdns-recursor
- Arch Linux update for powerdns
- Fedora 24 update for pdns-recursor
- Fedora 25 update for pdns-recursor
- Fedora EPEL 7 update for pdns-recursor
- Fedora EPEL 6 update for pdns-recursor
- Fedora EPEL 7 update for pdns
- Fedora 25 update for pdns
- Fedora 24 update for pdns