CVE-2020-12244: High severity powerdns vulnerability
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12244?
CVE-2020-12244 is a vulnerability in PowerDNS Recursor 4.1.0 through 4.3.0 that allows an attacker to bypass DNSSEC validation.
How does CVE-2020-12244 affect PowerDNS Recursor?
CVE-2020-12244 affects PowerDNS Recursor versions 4.1.0 through 4.3.0 by allowing an attacker to bypass DNSSEC validation.
What is the severity of CVE-2020-12244?
The severity of CVE-2020-12244 is high with a CVSS score of 7.5.
How can I fix CVE-2020-12244?
To fix CVE-2020-12244, update PowerDNS Recursor to version 4.3.1 or later.
Where can I find more information about CVE-2020-12244?
You can find more information about CVE-2020-12244 in the following references: <ul><li><a href='http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00052.html'>http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00052.html</a></li><li><a href='http://www.openwall.com/lists/oss-security/2020/05/19/3'>http://www.openwall.com/lists/oss-security/2020/05/19/3</a></li><li><a href='https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-02.html'>https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-02.html</a></li></ul>