PT-2020-12479 · Powerdns+1 · Powerdns Recursor+1

Anat Bremler-Barr

+2

·

Published

2020-05-19

·

Updated

2024-06-15

·

CVE-2020-10995

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PowerDNS Recursor versions 4.1.0 through 4.3.0
Description The issue in the DNS protocol allows malicious parties to use recursive DNS services to attack third-party authoritative name servers, resulting in degraded performance. This is triggered by random subdomains in the NSDNAME in NS records. The attack uses a crafted reply by an authoritative name server to amplify the resulting traffic between the recursive and other authoritative name servers.
Recommendations For PowerDNS Recursor versions 4.1.0 through 4.1.15, consider updating to version 4.1.16 to mitigate the impact of this issue. For PowerDNS Recursor versions 4.2.0 through 4.2.1, consider updating to version 4.2.2 to mitigate the impact of this issue. For PowerDNS Recursor versions 4.3.0, consider updating to version 4.3.1 to mitigate the impact of this issue.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10995
DSA-4691-1
MGASA-2020-0223
OPENSUSE-SU-2020:0698-1
OPENSUSE-SU-2020_0698-1
OPENSUSE-SU-2024:11157-1

Affected Products

Powerdns Recursor
Suse