MGASA-2020-0286

Source
https://advisories.mageia.org/MGASA-2020-0286.html
Import Source
https://advisories.mageia.org/MGASA-2020-0286.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0286
Related
Published
2020-07-07T13:47:37Z
Modified
2020-07-07T13:15:44Z
Summary
Updated pdns-recursor packages fix security vulnerability
Details

Updated pdns-recursor package fixes security vulnerability:

An issue has been found in PowerDNS Recursor where the ACL applied to the internal web server via webserver-allow-from is not properly enforced, allowing a remote attacker to send HTTP queries to the internal web server, bypassing the restriction (CVE-2020-14196).

In the default configuration the API webserver is not enabled. Only installations using a non-default value for webserver and webserver-address are affected.

References
Credits

Affected packages

Mageia:7 / pdns-recursor

Package

Name
pdns-recursor
Purl
pkg:rpm/mageia/pdns-recursor?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.17-1.mga7

Ecosystem specific

{
    "section": "core"
}