freebsd-ports/dns/powerdns-recursor
Jochen Neumeister d11cb62dd2 Update to 4.3.2
This update contains a security fix for CVE-2020-14196.

The issue is:

CVE-2020-14196: An issue has been found in PowerDNS Recursor where the ACL applied to the internal web server via webserver-allow-from is not properly enforced, allowing a remote attacker to send HTTP queries to the internal web server, bypassing the restriction.

In the default configuration the API webserver is not enabled. Only installations using a non-default value for webserver and webserver-address are affected.

As usual, there were also other smaller enhancements and bugfixes. In particular, the 4.3.2 release contains fixes that allow long CNAME chains to resolve properly, where previously they could fail if qname minimization is enabled.

PR:		247707
Submitted by:	Ralf van der Enden <tremere@cainites.net> (maintainer)
MFH:		2020Q3
Security:	641cd669-bc37-11ea-babf-6805ca2fa271
Sponsored by:	Netzkommune GmbH
2020-07-02 10:20:52 +00:00
..
files Update to 4.3.2 2020-07-02 10:20:52 +00:00
distinfo Update to 4.3.2 2020-07-02 10:20:52 +00:00
Makefile Update to 4.3.2 2020-07-02 10:20:52 +00:00
pkg-descr
pkg-plist