PowerDNS Authoritative Server 3.4.11 and Recursor 3.7.4 released!

Jan 13, 2017

Today, we are releasing version 3.4.11 of the PowerDNS Authoritative Server and version 3.7.4 of the PowerDNS Recursor. These releases fix several security issues that were reported to PowerDNS.

It concerns the following security advisories:

  • 2016-02: Crafted queries can cause abnormal CPU usage
  • 2016-03: Denial of service via the web server (Authoritative only)
  • 2016-04: Insufficient validation of TSIG signatures (Authoritative only)
  • 2016-05: Crafted zone record can cause a denial of service (Authoritative only)

For those who cannot update, minimal patches are available (2016-02, 2016-03, 2016-04, 2016-05).

A few other issues have been fixed as well, see the Authoritative Server 3.4.11 changelog and the Recursor 3.7.4 changelog.

We urge all users to upgrade to these new versions.

Source tarballs and packages are available on:

About the author

Pieter Lexis

Pieter Lexis

Senior Developer at PowerDNS

Related Articles

PowerDNS Authoritative Server 3.4.6 released

We’re pleased to announce the release of the PowerDNS Authoritative Server version 3.4.6. This release fixes some bugs and...

Pieter Lexis 08/6/15

PowerDNS Authoritative Server 3.4.7 released

We’re pleased announce the release of the PowerDNS Authoritative Server version 3.4.7. This release fixes several bugs and...

Pieter Lexis 11/3/15

PowerDNS Recursor 4.0.4 released!

We are happy to announce the release of the PowerDNS Recursor version 4.0.4. This release fixes 2 security issues and adds...

Pieter Lexis 01/6/17

PowerDNS Recursor 4.0.3 released

A new release for the PowerDNS Recursor with version 4.0.3 is available. This release has many fixes and improvements in the...

Pieter Lexis 09/3/16