CVE-2020-12244
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2020-12244 affects PowerDNS Recursor versions 4.1.0 through 4.3.0. The vulnerability was discovered by Matt Nordhoff and publicly disclosed on May 19, 2020. The issue impacts the DNSSEC validation functionality in PowerDNS Recursor, a non-authoritative/recursing DNS server (PowerDNS Advisory).

Technical details

The vulnerability exists in the SyncRes::processAnswer functionality where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated. This vulnerability has been assigned a medium severity rating (PowerDNS Advisory, OSS Security).

Impact

The vulnerability allows an attacker in position of man-in-the-middle to send a NXDOMAIN answer for a name that does exist, effectively bypassing DNSSEC validation (PowerDNS Advisory).

Exploitability

The vulnerability requires an attacker to be in a man-in-the-middle position to exploit. No public exploits were reported at the time of disclosure (PowerDNS Advisory).

Mitigation and workarounds

The issue was fixed in PowerDNS Recursor versions 4.3.1, 4.2.2, and 4.1.16. Users are advised to upgrade to these or newer versions. No workarounds are available for this vulnerability (OSS Security, PowerDNS Advisory).

Community reactions

Multiple Linux distributions released security updates to address this vulnerability, including Debian with DSA-4691-1, Fedora with updates for versions 31 and 32, and OpenSUSE with update SU-2020:0698-1 (Debian Security, Fedora Update, OpenSUSE Security).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9318MEDIUM4.8
  • Linux Debian logoLinux Debian
  • taglib
NoNoAug 12, 2026
CVE-2026-19566NONEN/A
  • Linux Debian logoLinux Debian
  • libnet-cidr-set-perl
NoNoAug 12, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 12, 2026
CVE-2026-68449NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 12, 2026
CVE-2026-68448NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management