PowerDNS Recursor 4.0.4 released!

Jan 13, 2017

We are happy to announce the release of the PowerDNS Recursor version 4.0.4. This release fixes 2 security issues and adds several improvements to the DNSSEC validation code.

The following PowerDNS Security Advisories are fixes:

  • 2016-02: Crafted queries can cause abnormal CPU usage
  • 2016-04: Insufficient validation of TSIG signatures

Minimal patches are available for those unable to fully upgrade (2016-02, 2016-04)

The full changelog is available, highlights include:

  • Check TSIG signature on IXFR (Security Advisory 2016-04)
  • Don’t parse spurious RRs in queries when we don’t need them (Security Advisory 2016-02)
  • Add `max-recursion-depth` to limit the number of internal recursion
  • Wait until after daemonizing to start the RPZ and protobuf threads
  • On RPZ customPolicy, follow the resulting CNAME
  • Make the negcache forwarded zones aware
  • Cache records for zones that were delegated to from a forwarded zone
  • DNSSEC: don’t go bogus on zero configured DSs
  • DNSSEC: NSEC3 optout and Bogus insecure forward fixes
  • DNSSEC: Handle CNAMEs at the apex of secure zones to other secure zones

We recommend all users of the Recursor to upgrade to this version. Tarballs with sources are available (signature).

Packages for Debian Stable, Ubuntu Trusty, Xenial and Wily and CentOS 6 and 7 are available from our repositories.

About the author

Pieter Lexis

Pieter Lexis

Senior Developer at PowerDNS

Categories

Related Articles

PowerDNS Authoritative Server 4.9.0

This is release 4.9.0 of the Authoritative Server. It brings a few new features, and a collection of small improvements and...

Peter van Dijk Mar 15, 2024

PowerDNS Recursor: Extended DNS Errors Help You Troubleshooting

This is the seventh episode of a series of blog posts we are publishing, mostly around recent developments with respect to...

Otto Moerbeek Mar 12, 2024

PowerDNS Recursor 4.8.7, 4.9.4 and 5.0.3 Released

Today we have released PowerDNS Recursor 4.8.7, 4.9.4 and 5.0.3. These releases are maintenance releases that fix a few...

Otto Moerbeek Mar 7, 2024

PowerDNS Authoritative Server 4.9.0-beta2

This is release 4.9.0-beta2 (beta1 was not released, due to a tagging mistake) of the Authoritative Server. It brings a few...

Peter van Dijk Feb 16, 2024