Index: vuln.xml =================================================================== --- vuln.xml (revision 552303) +++ vuln.xml (working copy) @@ -58,6 +58,38 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + powerdns-recursor -- cache pollution + + + powerdns-recursor + 4.3.04.3.4 + 4.2.04.2.4 + 4.1.04.1.17 + + + + +

PowerDNS Team reports:

+
+

CVE-2020-25829: An issue has been found in PowerDNS Recursor where a remote attacker can cause the + cached records for a given name to be updated to the ‘Bogus’ DNSSEC validation state, instead of + their actual DNSSEC ‘Secure’ state, via a DNS ANY query. This results in a denial of service for + installations that always validate (dnssec=validate) and for clients requesting validation when + on-demand validation is enabled (dnssec=process).

+
+ +
+ + https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html + CVE-2020-25829 + + + 2020-10-13 + 2020-10-14 + +
+ Flash Player -- arbitrary code execution