rpm package
suse/pdns-recursor&distro=SUSE Package Hub 15 SP2
pkg:rpm/suse/pdns-recursor&distro=SUSE%20Package%20Hub%2015%20SP2
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-25829 | — | < 4.3.5-bp152.2.12.1 | 4.3.5-bp152.2.12.1 | Oct 16, 2020 | An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY q | ||
| CVE-2020-14196 | — | < 4.3.5-bp152.2.12.1 | 4.3.5-bp152.2.12.1 | Jul 1, 2020 | In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced. |
- CVE-2020-25829Oct 16, 2020affected < 4.3.5-bp152.2.12.1fixed 4.3.5-bp152.2.12.1
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY q
- CVE-2020-14196Jul 1, 2020affected < 4.3.5-bp152.2.12.1fixed 4.3.5-bp152.2.12.1
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.