PowerDNS does not respond to certain queries it considers malformed. This in
itself is not a problem, and was even thought of as a security measure.
Brian and Florian have discovered that not answering a query for an invalid DNS
record within a valid domain allows for a larger spoofing window of the valid
domain. Because of the Kaminsky-discovery, this has become bad.
For a sophisticated attacker, this provides no benefit. However, such a long
window allows unsophisticated hackers to achieve better results.