Hi all,

We released PowerDNS Authoritative Server 4.1.7 and 4.0.7 today, fixing an 
important security issue in the HTTP remote backend that has recently been 
reported to us.  Setups that are not using this backend are not impacted by 
this issue.  More information can be found in the corresponding security 

- PowerDNS Security Advisory 2019-03 (CVE-2019-3871): Insufficient validation 
in the HTTP remote backend[1]

It affects PowerDNS Authoritative Server up to and including 4.1.6.  Please 
note that at the time of writing, PowerDNS Authoritative Server 3.4 and below 
are no longer supported, as described in 
https://doc.powerdns.com/authoritative/appendices/EOL.html .

Minimal patches are available at 
https://downloads.powerdns.com/patches/2019-03/ .

The 4.0.7 changelog[2]:

- #7582: Insufficient validation in the HTTP remote backend

The 4.1.7 changelog[3]:

- #7577: Insufficient validation in the HTTP remote backend

The 4.0.7 tarball[4] (sig[5]) and 4.1.7 tarball[6] (sig[7]) are available at 
downloads.powerdns.com and packages for CentOS 6 and 7, Debian Jessie and 
Stretch, Ubuntu Bionic, Trusty and Xenial are available from repo.powerdns.com.

Please send us all feedback and issues you might have via the mailing list[8], 
or in case of a bug, via GitHub[9].

[2] https://doc.powerdns.com/authoritative/changelog/4.0.html#change-4.0.7
[3] https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.7
[4] https://downloads.powerdns.com/releases/pdns-4.0.7.tar.bz2
[5] https://downloads.powerdns.com/releases/pdns-4.0.7.tar.bz2.sig
[6] https://downloads.powerdns.com/releases/pdns-4.1.7.tar.bz2
[7] https://downloads.powerdns.com/releases/pdns-4.1.7.tar.bz2.sig
[8] https://mailman.powerdns.com/mailman/listinfo/pdns-users
[9] https://github.com/PowerDNS/pdns/issues/new
Erik Winkels
PowerDNS.COM BV -- https://www.powerdns.com

Attachment: signature.asc
Description: PGP signature

Pdns-users mailing list

Reply via email to