VDB

DEBIAN-CVE-2019-3807

DEBIAN-CVE-2019-3807 PUBLISHED CVSS 9.800000190734863 CRITICAL

An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.

Risk Scores

CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:13pdns-recursor0, 0, 0
Debian:11pdns-recursor0, 0, 0
Debian:14pdns-recursor0, 0, 0
Debian:12pdns-recursor0, 0, 0

Timeline

  • Jan 29, 2019 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›