MGASA-2019-0122
Dashboard / Vulnerabilities / MGASA-2019-0122
Summary: Updated pdns packages fix security vulnerability
Details: Updated pdns packages fix security vulnerability: An issue has been found in PowerDNS Authoritative Server when the HTTP remote backend is used in RESTful mode (without post=1 set), allowing a remote user to cause the HTTP backend to connect to an attacker-specified host instead of the configured one, via a crafted DNS query. This can be used to cause a denial of service by preventing the remote backend from getting a response, content spoofing if the attacker can time its own query so that subsequent queries will use an attacker-controlled HTTP server instead of the configured one, and possibly information disclosure if the Authoritative Server has access to internal servers (CVE-2019-3871).
References: https://advisories.mageia.org/MGASA-2019-0122.html, https://bugs.mageia.org/show_bug.cgi?id=24531, https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-03.html
Affected packages
Package
Name: pdns
Purl: pkg:rpm/mageia/pdns?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
