First published: Mon Jan 04 2010(Updated: )
<a href="https://access.redhat.com/security/cve/CVE-2009-4009">CVE-2009-4009</a>, <a href="https://access.redhat.com/security/cve/CVE-2009-4010">CVE-2009-4010</a> <span class="quote">> This Wednesday the release of the PowerDNS Recursor 3.1.7.2 will be made > public, which fixes two important security issues, one of which is remotely > exploitable. > > Given the critical nature of these vulnerabilities, we are trying to keep > details confidential for a few more days. > > Summary > ------- > The short version: please contact me off-list if you distribute the PowerDNS > Recursor (any version), and if you want to gain early access to version > 3.1.7.2 and associated release notes. > > Details > ------- > The two security issues have been discovered by two parties which we cannot > yet publicly mention or thank, but they deserve full credit and gratitude > for their discoveries. > > Two CVE numbers have been requested, they will be communicated ASAP. > > One issue is remotely exploitable, and there are no configuration > countermeasures. The other allows a (skilled) attacker to spoof domain data > for domain names he does not own. > > The first issue is at least a DoS, but in all likelihood can be expanded > into a full compromise ('rooted'). > > The release that will be made public is already available for distributors. > Other good news is that it is already serving over a million ISP customers, > with no apparent problems. > > Contact me off-list for quick access to the new PowerDNS Recursor code, > patch & release notes. > > If you need any kind of assistance in doing a smooth upgrade, also do not > hesitate to contact me.</span>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PowerDNS Recursor | =3.1.7 | |
PowerDNS Recursor | =3.1 | |
PowerDNS Recursor | =2.9.18 | |
PowerDNS Recursor | =2.0_rc1 | |
PowerDNS Recursor | =3.1.2 | |
PowerDNS Recursor | =3.0 | |
PowerDNS Recursor | =2.9.15 | |
PowerDNS Recursor | =3.1.5 | |
PowerDNS Recursor | =3.1.1 | |
PowerDNS Recursor | =3.0.1 | |
PowerDNS Recursor | <=3.1.7.2 | |
PowerDNS Recursor | =2.9.17 | |
PowerDNS Recursor | =3.1.7.1 | |
PowerDNS Recursor | =2.8 | |
PowerDNS Recursor | =3.1.3 | |
PowerDNS Recursor | =2.9.16 | |
PowerDNS Recursor | =3.1.4 | |
PowerDNS Recursor | =3.1.6 | |
redhat/3.1.7.2 | <1.el5 | 1.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.