Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:2354-1

Опубликовано: 23 сент. 2016
Источник: suse-cvrf

Описание

Security update for pdns

This update for pdns fixes the following issues:

  • CVE-2016-5426, CVE-2016-5427: Fix case where crafted queries can cause unexpected backend load. (boo#998159)

Список пакетов

openSUSE Leap 42.1
pdns-3.4.6-6.2
pdns-backend-ldap-3.4.6-6.2
pdns-backend-lua-3.4.6-6.2
pdns-backend-mydns-3.4.6-6.2
pdns-backend-mysql-3.4.6-6.2
pdns-backend-postgresql-3.4.6-6.2
pdns-backend-sqlite3-3.4.6-6.2

Описание

PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.


Затронутые продукты
openSUSE Leap 42.1:pdns-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-ldap-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-lua-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-mydns-3.4.6-6.2

Ссылки

Описание

PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.


Затронутые продукты
openSUSE Leap 42.1:pdns-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-ldap-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-lua-3.4.6-6.2
openSUSE Leap 42.1:pdns-backend-mydns-3.4.6-6.2

Ссылки