High severity7.5NVD Advisory· Published May 19, 2020· Updated Jun 17, 2026
CVE-2020-12244
CVE-2020-12244
Description
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- PowerDNS/PowerDNS Recursordescription
- osv-coords4 versionspkg:rpm/opensuse/pdns-recursor&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/pdns-recursor&distro=openSUSE%20Tumbleweedpkg:rpm/suse/pdns-recursor&distro=SUSE%20Package%20Hub%2012%20SP1pkg:rpm/suse/pdns-recursor&distro=SUSE%20Package%20Hub%2015%20SP1
< 4.1.12-bp151.4.3.1+ 3 more
- (no CPE)range: < 4.1.12-bp151.4.3.1
- (no CPE)range: < 4.5.5-1.3
- (no CPE)range: < 4.1.12-bp151.4.3.1
- (no CPE)range: < 4.1.12-bp151.4.3.1
Patches
Vulnerability mechanics
References
6- lists.opensuse.org/opensuse-security-announce/2020-05/msg00052.htmlnvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2020/05/19/3nvdMailing ListThird Party Advisory
- doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-02.htmlnvdVendor Advisory
- www.debian.org/security/2020/dsa-4691nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMP72NJGKBWR5WEBXAWX5KSLQUDFTG6S/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PS4ZN5XGENYNFKX7QIIOUCQQHXE37GJF/nvd
News mentions
0No linked articles in our index yet.