rpm package
opensuse/pdns-recursor&distro=openSUSE Leap 15.2
pkg:rpm/opensuse/pdns-recursor&distro=openSUSE%20Leap%2015.2
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-25829 | — | < 4.3.5-bp152.2.12.1 | 4.3.5-bp152.2.12.1 | Oct 16, 2020 | An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY q | ||
| CVE-2020-14196 | — | < 4.1.12-bp151.4.6.1 | 4.1.12-bp151.4.6.1 | Jul 1, 2020 | In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced. |
- CVE-2020-25829Oct 16, 2020affected < 4.3.5-bp152.2.12.1fixed 4.3.5-bp152.2.12.1
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY q
- CVE-2020-14196Jul 1, 2020affected < 4.1.12-bp151.4.6.1fixed 4.1.12-bp151.4.6.1
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.