Описание
Security update for pdns
This update for pdns fixes the following issues:
- CVE-2016-5426, CVE-2016-5427: Fix case where crafted queries can cause unexpected backend load. (boo#998159)
Список пакетов
openSUSE Leap 42.1
pdns-3.4.6-6.2
pdns-backend-ldap-3.4.6-6.2
pdns-backend-lua-3.4.6-6.2
pdns-backend-mydns-3.4.6-6.2
pdns-backend-mysql-3.4.6-6.2
pdns-backend-postgresql-3.4.6-6.2
pdns-backend-sqlite3-3.4.6-6.2
Ссылки
- E-Mail link for openSUSE-SU-2016:2354-1
- SUSE Security Ratings
Описание
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
Затронутые продукты
openSUSE Leap 42.1:pdns-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-ldap-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-lua-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-mydns-3.4.6-6.2
Ссылки
- CVE-2016-5426
- SUSE Bug 998159
Описание
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.
Затронутые продукты
openSUSE Leap 42.1:pdns-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-ldap-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-lua-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-mydns-3.4.6-6.2
Ссылки
- CVE-2016-5427
- SUSE Bug 998159