We’ve released PowerDNS Authoritative Server 4.0.6 & 4.1.5 and Recursor 4.0.9 & 4.1.5.
These are security releases with additional minor improvements and bug fixes.
Minimal patches for the releases are available at https://downloads.powerdns.com/patches/.
The changelogs look as follows:
Authoritative Server 4.1.5
This release fixes the following security advisories:
- PowerDNS Security Advisory 2018-03 (CVE-2018-10851)
- PowerDNS Security Advisory 2018-05 (CVE-2018-14626)
Improvements
Bug Fixes
Authoritative Server 4.0.6
This release fixes PowerDNS Security Advisory 2018-03 (CVE-2018-10851).
Bug fixes
Improvements
Recursor 4.1.5
This release fixes the following security advisories:
- PowerDNS Security Advisory 2018-04 (CVE-2018-10851)
- PowerDNS Security Advisory 2018-06 (CVE-2018-14626)
- PowerDNS Security Advisory 2018-07 (CVE-2018-14644)
Improvements
- Add pdnslog to lua configuration scripts (Chris Hofstaedtler) (#6919, #6848)
- Fix compilation with libressl 2.7.0+ (#6948, #6943)
- Export outgoing ECS value and server ID in protobuf (if any) (#7004, #6991, #6989)
- Switch to devtoolset 7 for el6 (#7122, #7040)
- Allow the signature inception to be off by a number of seconds (Kees Monshouwer) (#7125, #7081)
Bug Fixes
- Crafted answer can cause a denial of service (CVE-2018-10851, #7151)
- Packet cache pollution via crafted query (CVE-2018-14626, #7151)
- Crafted query for meta-types can cause a denial of service (CVE-2018-14644, #7151)
- Delay the creation of rpz threads until we have dropped privileges (#6984 #6792)
- Cleanup the netmask trees used for the ecs index on removals (#6961 #6960)
- Make sure that the ecs scope from the auth is < to the source (#6963, #6605)
- Authority records in aa=1 cname answer are authoritative (#6980, #6979)
- Avoid a memory leak in catch-all exception handler (#7073)
- Don’t require authoritative answers for forward-recurse zones (#6741, #6340)
- Release memory in case of error in the openssl ecdsa constructor (#6917)
- Convert a few uses to toLogString to print DNSName’s that may be empty in a safer manner (#6925, #6924)
- Avoid a crash on DEC Alpha systems (#6945)
- Clear all caches on (N)TA changes (#6951, #6949)
Recursor 4.0.9
This release fixes the following security advisories:
- PowerDNS Security Advisory 2018-04 (CVE-2018-10851)
- PowerDNS Security Advisory 2018-06 (CVE-2018-14626)
- PowerDNS Security Advisory 2018-07 (CVE-2018-14644)
Bug fixes
- Crafted answer can cause a denial of service (CVE-2018-10851, #7152)
- Packet cache pollution via crafted query (CVE-2018-14626, #7152)
- Crafted query for meta-types can cause a denial of service (CVE-2018-14644, #7152)
The tarballs and signatures are available at downloads.powerdns.com and packages for CentOS 6 and 7, Debian Jessie and Stretch, Ubuntu Bionic, Trusty and Xenial are available from repo.powerdns.com. Raspberry PI packages will follow tomorrow.
Please send us all feedback and issues you might have via the mailing list, or in case of a bug, via GitHub.