PT-2020-12479 · Powerdns+1 · Powerdns Recursor+1
Anat Bremler-Barr
+2
·
Published
2020-05-19
·
Updated
2024-06-15
·
CVE-2020-10995
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PowerDNS Recursor versions 4.1.0 through 4.3.0
Description
The issue in the DNS protocol allows malicious parties to use recursive DNS services to attack third-party authoritative name servers, resulting in degraded performance. This is triggered by random subdomains in the NSDNAME in NS records. The attack uses a crafted reply by an authoritative name server to amplify the resulting traffic between the recursive and other authoritative name servers.
Recommendations
For PowerDNS Recursor versions 4.1.0 through 4.1.15, consider updating to version 4.1.16 to mitigate the impact of this issue.
For PowerDNS Recursor versions 4.2.0 through 4.2.1, consider updating to version 4.2.2 to mitigate the impact of this issue.
For PowerDNS Recursor versions 4.3.0, consider updating to version 4.3.1 to mitigate the impact of this issue.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerdns Recursor
Suse