{"id":"MGASA-2018-0252","summary":"Updated pdns-recursor package fixes security vulnerability","details":"An issue has been found in the DNSSEC validation component of PowerDNS\nRecursor, allowing an ancestor delegation NSEC or NSEC3 record to be\nused to wrongfully prove the non-existence of a RR below the owner name\nof that record. This would allow an attacker in position of\nman-in-the-middle to send a NXDOMAIN answer for a name that does exist\n(CVE-2018-1000003).\n","modified":"2026-02-04T02:36:45.412474Z","published":"2018-05-24T16:30:31Z","related":["CVE-2018-1000003"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0252.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=22935"},{"type":"REPORT","url":"https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2018-01.html"},{"type":"REPORT","url":"https://blog.powerdns.com/2018/03/29/powerdns-recursor-4-1-2-released/"},{"type":"REPORT","url":"https://lists.opensuse.org/opensuse-updates/2018-04/msg00033.html"}],"affected":[{"package":{"name":"pdns-recursor","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/pdns-recursor?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.2-3.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0252.json"}}],"schema_version":"1.7.3","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}