PowerDNS Recursor 4.1.9 Released

Jan 21, 2019

We are very happy to announce the 4.1.9 release of the PowerDNS Recursor. This release is fixing two security issues, and addressing a shortcoming in the way incoming queries are distributed to threads under heavy load.This release fixes the following security issues:

  • PowerDNS Security Advisory 2019-01 (CVE-2019-3806): Lua hooks are not called over TCP
  • PowerDNS Security Advisory 2019-02 (CVE-2019-3807): DNSSEC validation is not performed for AA=0 responses

These issues respectively affect PowerDNS Recursor from 4.1.4 and 4.1.0, up to and including 4.1.8.  PowerDNS Recursor 4.0.x and below are not affected.

Minimal patches are available at https://downloads.powerdns.com/patches/2019-01/ and https://downloads.powerdns.com/patches/2019-02/.

The changelog:

  • #7397: Load the Lua script in the distributor thread, check signature for AA=0 answers (CVE-2019-3806, CVE-2019-3807)
  • #7377: Try another worker before failing if the first pipe was full

The tarball (signature) is available at downloads.powerdns.com and packages for CentOS 6 and 7, Debian Jessie and Stretch, Ubuntu Bionic, Trusty and Xenial are available from repo.powerdns.com.

Please send us all feedback and issues you might have via the mailing list, or in case of a bug, via GitHub.

About the author

Remi Gacogne

Remi Gacogne

Senior Developer at PowerDNS

Categories

Related Articles

PowerDNS Authoritative Server 3.4.6 released

We’re pleased to announce the release of the PowerDNS Authoritative Server version 3.4.6. This release fixes some bugs and...

Pieter Lexis 08/6/15

PowerDNS Recursor 4.0.4 released!

We are happy to announce the release of the PowerDNS Recursor version 4.0.4. This release fixes 2 security issues and adds...

Pieter Lexis 01/6/17

PowerDNS Authoritative Server 3.4.11 and Recursor 3.7.4 released!

Today, we are releasing version 3.4.11 of the PowerDNS Authoritative Server and version 3.7.4 of the PowerDNS Recursor....

Pieter Lexis 01/6/17

Authoritative Server 3.4.4

Hi everybody, We’re pleased to announce version 3.4.4 of our Authoritative Server. The most important part of this update is...

Peter van Dijk 04/5/15