Denial of Service in PowerDNS Authoritative Server
ID: | DSA-3306-1 |
Distribution: | Debian |
Plattformen: | Debian sid, Debian jessie, Debian stretch |
Datum: | Fr, 10. Juli 2015, 06:38 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1868 |
Applikationen: | PowerDNS Authoritative Server |
Originalnachricht |
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3306-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini July 09, 2015 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : pdns CVE ID : CVE-2015-1868 Toshifumi Sakaguchi discovered that the patch applied to pdns, an authoritative DNS server, fixing CVE-2015-1868, was insufficient in some cases, allowing remote attackers to cause a denial of service (service-affecting CPU spikes and in some cases a crash). For the stable distribution (jessie), this problem has been fixed in version 3.4.1-4+deb8u2. For the testing distribution (stretch), this problem has been fixed in version 3.4.5-1. For the unstable distribution (sid), this problem has been fixed in version 3.4.5-1. We recommend that you upgrade your pdns packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJVnvFOAAoJEK+lG9bN5XPLALwQAJndRouw2GWPmB5nvnTzpitD ls+qBdjDEyfq9E7zisBNBkgbip46yL3tl8oxunFNPrHPHjjbVhhXPDmh3IiFhuw0 nGgyfwsnOEhsIU/sGt5j6DW86wH66RWZzpEaf0x7geQEq4vhWYNPKyN4zNgJNkwp isBInxAu8VUyiZDQOi7TA+RMhnRX9IWMWnQ2QdIKi5Qo51Dig8BrZLoXTIlngoaV sVQWDRUZ8lNTyuGDDL3WkOo7RzS5ytOS2odzN44MiIcOX81SPOeRFriEprQVOJzP nvoDHmOMNYbt7o2jVJAubQ4e8FXC7U/8qUkYJu/xdfkZIoq/pEkMIKh78D2G8zuR P7IqpTOLZL1KKFT4qoUS7uFV7gC1hQXMRpdCbT179MTzin6ex4FEdU+r94mndbbu 1CHUSSYYWPqXPAtYvpvyv8bhs8/8uKZzmsgPVlDeupXOA4YsbGoMuickMUHlmkbL e+RFbOJ5hhYvF1z7h8zIHc7d1ev3PmJBijqvTWNQQFQqPm7F6tUMa20V35mAx0ES ZW6pJxzaXgMLl33k3jDWCj5zByJr4RPcUWjP4usjPe1pRub/MqX1bQ5YpO1HtkDM XGH6C7Bn66LMM0GQlW83foOhR48HvgJFXMtVoUFHA8bIQM/bpmk0bkN75r7nntL2 VTbvAg5P3pcxcM5+jE+1 =Tki9 -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org Archive: https://lists.debian.org/559ef150.21dbb40a.b9da2.072b@mx.google.com |