Updated pdns-recursor packages fix security vulnerability
Publication date: 07 Jul 2020Modification date: 07 Jul 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-14196
Description
Updated pdns-recursor package fixes security vulnerability: An issue has been found in PowerDNS Recursor where the ACL applied to the internal web server via webserver-allow-from is not properly enforced, allowing a remote attacker to send HTTP queries to the internal web server, bypassing the restriction (CVE-2020-14196). In the default configuration the API webserver is not enabled. Only installations using a non-default value for webserver and webserver-address are affected.
References
SRPMS
7/core
- pdns-recursor-4.1.17-1.mga7