MGASA-2019-0051

Source
https://advisories.mageia.org/MGASA-2019-0051.html
Import Source
https://advisories.mageia.org/MGASA-2019-0051.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0051
Related
Published
2019-01-23T15:50:09Z
Modified
2019-01-23T15:14:27Z
Summary
Updated pdns-recursor package fixes security vulnerabilities
Details

An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806).

An issue has been found in PowerDNS Recursor where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation (CVE-2019-3807).

References
Credits

Affected packages

Mageia:6 / pdns-recursor

Package

Name
pdns-recursor
Purl
pkg:rpm/mageia/pdns-recursor?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.9-1.mga6

Ecosystem specific

{
    "section": "core"
}