Today, we are releasing version 3.4.11 of the PowerDNS Authoritative Server and version 3.7.4 of the PowerDNS Recursor. These releases fix several security issues that were reported to PowerDNS.
It concerns the following security advisories:
- 2016-02: Crafted queries can cause abnormal CPU usage
- 2016-03: Denial of service via the web server (Authoritative only)
- 2016-04: Insufficient validation of TSIG signatures (Authoritative only)
- 2016-05: Crafted zone record can cause a denial of service (Authoritative only)
For those who cannot update, minimal patches are available (2016-02, 2016-03, 2016-04, 2016-05).
A few other issues have been fixed as well, see the Authoritative Server 3.4.11 changelog and the Recursor 3.7.4 changelog.
We urge all users to upgrade to these new versions.
Source tarballs and packages are available on:
- The downloads website
- Soon: RHEL/CentOS Authoritative packages, with the usual huge thanks to Kees Monshouwer
- Soon: RHEL/CentOS Recursor packages, with the usual huge thanks to Kees Monshouwer