Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Debian 4.0 DSA-1544-1 Critical: Pdns-Recursor Cache Poisoning

debian
Calendar Grey April 9, 2008
Scroller Debian
Ubuntu Security Notice USN-4328-1 highlights vulnerability in libgcrypt; users should upgrade ASAP.
Amit Klein discovered that pdns-recursor, a caching DNS resolver, uses a weak random number generator to create DNS transaction IDs and UDP source port numbers

Summary


For the unstable distribution (sid), these problems have been fixed in
version 3.1.5-1.

We recommend that you upgrade your pdns-recursor package.

Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch

Size/MD5 checksum: 1198 e2afc6418e2640188aed92a15d852842
Size/MD5 checksum: 171270 e35d774e3282285a59a7f8038a036b61
Size/MD5 checksum: 34268 21442fd6cb034c874ae2c353d1bcd968

alpha architecture (DEC Alpha)

Size/MD5 checksum: 499010 6dd67b8950e778d9d2fd35114f5fc8f7

amd64 architecture (AMD x86_64 (AMD64))

Size/MD5...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.