CVE-2020-25829
published 2020-10-16CVE-2020-25829: An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.54%
93.0th percentile
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pdns-recursor | < pdns-recursor 4.3.5-1 (bookworm) | pdns-recursor 4.3.5-1 (bookworm) |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| powerdns | recursor | < 4.1.18 | 4.1.18 |
| powerdns | recursor | >= 4.2.0 < 4.2.5 | 4.2.5 |
| powerdns | recursor | >= 4.3.0 < 4.3.5 | 4.3.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2020-25829: pdns-recursor - An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, ...
vendor_debian·2020·CVSS 7.5
CVE-2020-25829 [HIGH] CVE-2020-25829: pdns-recursor - An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, ...
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process).
Scope: local
bookworm: resolved (fixed in 4.3.5-1)
bullseye: resolved (fixed in 4.3.5-1)
forky: resolved (fixed in 4.3.5-1)
sid: resolved (fixed in 4.3.5-1)
trixie: resolved (fixed in 4.3.5-1)
GHSA
GHSA-w93h-8xj5-rq44: An issue has been found in PowerDNS Recursor before 4
ghsa_unreviewed·2022-05-24
CVE-2020-25829 [HIGH] GHSA-w93h-8xj5-rq44: An issue has been found in PowerDNS Recursor before 4
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process).
OSV
CVE-2020-25829: An issue has been found in PowerDNS Recursor before 4
osv·2020-10-16·CVSS 7.5
CVE-2020-25829 [HIGH] CVE-2020-25829: An issue has been found in PowerDNS Recursor before 4
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS
bugzilla·2020-10-19·CVSS 7.5
CVE-2020-25829 [HIGH] CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS
CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS ANY query [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please
Bugzilla
CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS
bugzilla·2020-10-19·CVSS 7.5
CVE-2020-25829 [HIGH] CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS
CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS ANY query [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Ple
Bugzilla
CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS
bugzilla·2020-10-19·CVSS 7.5
CVE-2020-25829 [HIGH] CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS
CVE-2020-25829 pdns-recursor: remote attacker can cause the cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state instead of their actual DNSSEC ‘Secure’ state via a DNS ANY query
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process).
Reference:
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html
Discussion:
Crea
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00036.htmlhttps://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.htmlhttps://security.gentoo.org/glsa/202012-19http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00036.htmlhttps://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.htmlhttps://security.gentoo.org/glsa/202012-19
2020-10-16
Published