Bug 1839800

Summary: CVE-2020-10995 CVE-2020-12244 CVE-2020-10030 pdns-recursor: multiple vulnerabilities
Product: [Fedora] Fedora EPEL Reporter: Giuseppe Ragusa <giuseppe.ragusa>
Component: pdns-recursorAssignee: Ruben Kerkhof <ruben>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: epel7CC: ruben, sander
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: pdns-recursor-4.3.1-1.fc32 pdns-recursor-4.2.2-1.fc31 pdns-recursor-4.2.2-1.el8 pdns-recursor-4.1.16-1.el7 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-06-14 17:02:19 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Giuseppe Ragusa 2020-05-25 15:13:59 UTC
This bug was initially created as a copy of Bug #1257229

I am copying this bug because: 

Upstream reports three bugs in PowerDNS Recursor:

– CVE-2020-10995CVE-2020-12244CVE-2020-10030

PowerDNS Authoritative Server releases are not affected.

Upstream releases fixing the vulnerabilities:
4.3.1 (relevant for Fedora Rawhide and EPEL 8)
4.2.2 (maybe relevant for older Fedora maybe not relevant at all)
4.1.16 (relevant for EPEL 7)

Comment 1 Fedora Update System 2020-06-04 19:15:35 UTC
FEDORA-EPEL-2020-03f2097af0 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-03f2097af0

Comment 2 Fedora Update System 2020-06-04 19:15:36 UTC
FEDORA-2020-c0ff3df740 has been submitted as an update to Fedora 31. https://bodhi.fedoraproject.org/updates/FEDORA-2020-c0ff3df740

Comment 3 Fedora Update System 2020-06-04 19:15:38 UTC
FEDORA-2020-d9abb0c06d has been submitted as an update to Fedora 32. https://bodhi.fedoraproject.org/updates/FEDORA-2020-d9abb0c06d

Comment 4 Fedora Update System 2020-06-05 03:15:33 UTC
FEDORA-2020-d9abb0c06d has been pushed to the Fedora 32 testing repository.
In short time you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2020-d9abb0c06d`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-d9abb0c06d

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2020-06-05 03:26:10 UTC
FEDORA-EPEL-2020-03f2097af0 has been pushed to the Fedora EPEL 7 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-03f2097af0

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2020-06-05 03:39:09 UTC
FEDORA-EPEL-2020-21930ff650 has been pushed to the Fedora EPEL 8 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-21930ff650

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2020-06-05 03:52:29 UTC
FEDORA-2020-c0ff3df740 has been pushed to the Fedora 31 testing repository.
In short time you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2020-c0ff3df740`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-c0ff3df740

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2020-06-14 17:02:19 UTC
pdns-recursor-4.3.1-1.fc32 has been pushed to the Fedora 32 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2020-06-14 17:11:10 UTC
pdns-recursor-4.2.2-1.fc31 has been pushed to the Fedora 31 stable repository. If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2020-06-20 00:27:58 UTC
FEDORA-EPEL-2020-21930ff650 has been pushed to the Fedora EPEL 8 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 11 Fedora Update System 2020-06-20 00:35:17 UTC
FEDORA-EPEL-2020-03f2097af0 has been pushed to the Fedora EPEL 7 stable repository.
If problem still persists, please make note of it in this bug report.