CVE-2016-7074 log

Source
Severity Medium
Remote Yes
Type Insufficient validation
Description
An issue has been found in PowerDNS Authoritative Server and PowerDNS Recursor allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check that the TSIG record is the last one, leading to the possibility of parsing records that are not covered by the TSIG signature.
Group Package Affected Fixed Severity Status Ticket
AVG-148 powerdns-recursor 4.0.3-7 4.0.4-1 Medium Fixed
AVG-147 powerdns 4.0.1-7 4.0.2-1 Medium Fixed
Date Advisory Group Package Severity Description
19 Jan 2017 ASA-201701-30 AVG-148 powerdns-recursor Medium multiple issues
19 Jan 2017 ASA-201701-29 AVG-147 powerdns Medium multiple issues
References
http://seclists.org/oss-sec/2017/q1/97
https://doc.powerdns.com/md/security/powerdns-advisory-2016-04/
Notes
PowerDNS Authoritative Server up to and including 3.4.10 and 4.0.1 are affected. PowerDNS Recursor from 4.0.0 up to and including 4.0.3 are affected.