MGASA-2018-0252
Dashboard / Vulnerabilities / MGASA-2018-0252
Summary: Updated pdns-recursor package fixes security vulnerability
Details: An issue has been found in the DNSSEC validation component of PowerDNS Recursor, allowing an ancestor delegation NSEC or NSEC3 record to be used to wrongfully prove the non-existence of a RR below the owner name of that record. This would allow an attacker in position of man-in-the-middle to send a NXDOMAIN answer for a name that does exist (CVE-2018-1000003).
References: https://advisories.mageia.org/MGASA-2018-0252.html, https://bugs.mageia.org/show_bug.cgi?id=22935, https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2018-01.html, https://blog.powerdns.com/2018/03/29/powerdns-recursor-4-1-2-released/, https://lists.opensuse.org/opensuse-updates/2018-04/msg00033.html
Affected packages
Package
Name: pdns-recursor
Purl: pkg:rpm/mageia/pdns-recursor?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
