VDB

GCVE-110-MAGEIA-2020-393

GCVE-110-MAGEIA-2020-393
Advisory Published
Vulnetix · Advisory published October 24, 2020
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process). (CVE-2020-25829)

Affected Products

VendorProductVersionsPlatforms
Mageiapdns-recursor4.1.18-1.mga7 (unaffected), 0 (affected)

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›