PowerDNS Authoritative Server 4.0.7 and 4.1.7 Released

Mar 18, 2019

These two releases fix an issue with security implications that has been recently reported in the HTTP remote backend of the PowerDNS Authoritative Server. Setups that are not using this backend are not impacted by this issue. More information can be found in the corresponding security advisory:

It affects PowerDNS Authoritative Server up to and including 4.1.6. Please note that at the time of writing, PowerDNS Authoritative Server 3.4 and below are no longer supported, as described in https://doc.powerdns.com/authoritative/appendices/EOL.html.

Minimal patches are available at https://downloads.powerdns.com/patches/2019-03/.

The 4.0.7 changelog:

  • #7582: Insufficient validation in the HTTP remote backend

The 4.1.7 changelog:

  • #7577: Insufficient validation in the HTTP remote backend

The 4.0.7 tarball (signature) and 4.1.7 tarball (signature) are available at downloads.powerdns.com and packages for CentOS 6 and 7, Debian Jessie and Stretch, Ubuntu Bionic, Trusty and Xenial are available from repo.powerdns.com.

Please send us all feedback and issues you might have via the mailing list, or in case of a bug, via GitHub.

About the author

Peter van Dijk

Peter van Dijk

Senior Developer at PowerDNS

Related Articles

PowerDNS Authoritative Server 4.2.2 Released

This release fixes issues in the IXFR receive code, improves cache management, and corrects a few other small things. If you...

Peter van Dijk 04/5/20

PowerDNS Recursor 4.1.12 Released

This is a maintenance release with improvements for high-performance sites (and a wild bug fix appeared). The changelog:...

Erik Winkels 04/4/19

PowerDNS Recursor 4.1.15 Released

This is a maintenance release that fixes a few issues. In particular, a very slow creeping memory leak is plugged and an...

Otto Moerbeek 12/6/19

PowerDNS Recursor 4.1.13 Released

This is a maintenance release to optionally reduce the performance impact of memory-statistics collection and a fix in the...

Erik Winkels 05/3/19