opensuse backports-sle CVE-2020-25829 in OpenSuse and Powerdns Products
Published on October 16, 2020

product logo product logo
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process).

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2020-25829

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-25829 are published in these products:

 
 
 

Exploit Probability

EPSS
0.35%
Percentile
56.97%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.