Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian: DSA-1968-2 Severe: Pdns-Recursor Cache Poisoning Advisory

debian
Calendar Grey January 28, 2010
Debian Logo
Debian DSA-2021-4 reveals an update for nginx to address security flaws in the previous stable release.
It was discovered that pdns-recursor, the PowerDNS recursive name server, contains a cache poisoning vulnerability which may allow attackers to trick the server into serving incorr...

Summary

It was discovered that pdns-recursor, the PowerDNS recursive name server,
contains a cache poisoning vulnerability which may allow attackers to trick the
server into serving incorrect DNS data (CVE-2009-4010).

This DSA provides a security update for the old stable distribution
(etch), similar to the previous update in DSA-1968-1. (Note that the
etch version of pdns-recursor was not vulnerable to CVE-2009-4009.)

Extra care should be applied when installing this update. It is an etch
backport of the lenny version of the package (3.1.7 with security fixes
applied). Major differences in internal domain name processing made
backporting just the security fix too difficult.

For the old stable distribution (etch), this problem has been fixed in
version 3.1.4+v3.1.7-0+etch1.

We recommend that you upgrade your pdns-recursor package.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get pa...

Read the Full Advisory

Package: pdns-recursor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here