Vulnerabilities in PowerDNS Authoritative Server

Available updates for the authoritative DNS server PowerDNS Authoritative Server 4.3.1, 4.2.3, and 4.1.14, in which four vulnerabilities have been fixed , two of which could potentially lead to remote code execution by an attacker.

The vulnerabilities CVE-2020-24696, CVE-2020-24697, and CVE-2020-24698
affect code implementing the key exchange mechanism GSS-TSIG. The vulnerabilities only manifest when PowerDNS is built with GSS-TSIG support ("--enable-experimental-gss-tsig", which is not used by default) and can be exploited by sending specially crafted network packets. The vulnerabilities CVE-2020-24696 and CVE-2020-24698, caused by a race condition and double-free of memory, could lead to crashes or execution of arbitrary code by an attacker when processing requests with malformed GSS-TSIG signatures. The vulnerability CVE-2020-24697 is limited to denial of service. Since GSS-TSIG code was not used by default, including in distribution packages, and potentially contains other issues, it has been decided to completely remove it in the release of PowerDNS Authoritative 4.4.0.

CVE-2020-17482 may lead to information leakage from uninitialized memory of the process, but only manifests when processing requests from authenticated users who can add new records to the DNS zones managed by the server.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster