CVE-2020-24696: Race Condition
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can trigger a race condition leading to a crash, or possibly arbitrary code execution, by sending crafted queries with a GSS-TSIG signature.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in PowerDNS Authoritative?
The vulnerability ID for this issue in PowerDNS Authoritative is CVE-2020-24696.
What is the severity of CVE-2020-24696?
CVE-2020-24696 has a severity rating of 8.1 (high).
How does CVE-2020-24696 in PowerDNS Authoritative affect the system?
CVE-2020-24696 in PowerDNS Authoritative allows a remote, unauthenticated attacker to trigger a race condition leading to a crash or possibly arbitrary code execution by sending crafted queries with a GSS-TSIG signature.
Which version of PowerDNS Authoritative is affected by CVE-2020-24696?
PowerDNS Authoritative versions up to and including 4.3.0 are affected by CVE-2020-24696.
How can I learn more about CVE-2020-24696 in PowerDNS Authoritative?
You can find more information about CVE-2020-24696 in PowerDNS Authoritative in the following advisory: [powerdns-advisory-2020-06](https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-06.html).