Advisories ยป MGASA-2020-0286

Updated pdns-recursor packages fix security vulnerability

Publication date: 07 Jul 2020
Modification date: 07 Jul 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-14196

Description

Updated pdns-recursor package fixes security vulnerability:

An issue has been found in PowerDNS Recursor where the ACL applied to the
internal web server via webserver-allow-from is not properly enforced,
allowing a remote attacker to send HTTP queries to the internal web server,
bypassing the restriction (CVE-2020-14196).

In the default configuration the API webserver is not enabled. Only
installations using a non-default value for webserver and webserver-address 
are affected.
                

References

SRPMS

7/core