#VU17348 Security restrictions bypass in PowerDNS Recursor - CVE-2019-3807

 

#VU17348 Security restrictions bypass in PowerDNS Recursor - CVE-2019-3807

Published: February 1, 2019


Vulnerability identifier: #VU17348
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-3807
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
PowerDNS Recursor
Software vendor:
PowerDNS.COM B.V.

Description

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated. A remote attacker can bypass DNSSEC validation.


Remediation

Update to version 4.1.9.

External links