MGASA-2018-0252

Source
https://advisories.mageia.org/MGASA-2018-0252.html
Import Source
https://advisories.mageia.org/MGASA-2018-0252.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0252
Related
Published
2018-05-24T16:30:31Z
Modified
2018-05-24T15:35:45Z
Summary
Updated pdns-recursor package fixes security vulnerability
Details

An issue has been found in the DNSSEC validation component of PowerDNS Recursor, allowing an ancestor delegation NSEC or NSEC3 record to be used to wrongfully prove the non-existence of a RR below the owner name of that record. This would allow an attacker in position of man-in-the-middle to send a NXDOMAIN answer for a name that does exist (CVE-2018-1000003).

References
Credits

Affected packages

Mageia:6 / pdns-recursor

Package

Name
pdns-recursor
Purl
pkg:rpm/mageia/pdns-recursor?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.2-3.mga6

Ecosystem specific

{
    "section": "core"
}