First published: Tue Jan 29 2019(Updated: )
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PowerDNS Recursor | >=4.1.4<4.1.9 | |
>=4.1.4<4.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3806 is a vulnerability found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.
The severity of CVE-2019-3806 is high with a CVSS score of 8.1 (out of 10).
PowerDNS Recursor versions between 4.1.4 and 4.1.9 are affected by CVE-2019-3806.
To fix CVE-2019-3806, it is recommended to upgrade to PowerDNS Recursor version 4.1.9 or later.
You can find more information about CVE-2019-3806 in the following references: [1] [2]