An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pdns-recursor | Aug 22, 2024 | Jan 29, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 29, 2019 |
| Debian | — | Upgrade pdns-recursor | Feb 14, 2019 | Feb 14, 2019 |
| Freebsd | — | Upgrade powerdns-recursor | Jan 29, 2019 | Jan 22, 2019 |
| Suse | — | Upgrade pdns-recursor | Jan 31, 2019 | Jan 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub