Alerts This Week
Warning Icon 1 929
Alerts This Week
Warning Icon 1 929

Fedora 26: dnsdist Security Update 1.2.0 Critical: DoS Threat Fix

fedora
Calendar Grey August 31, 2017
Dist Fedora Esm H88
Upgrade to dnsdist 1.2.0 to address CVE-2016-7069 and CVE-2017-7557 vulnerabilities on Fedora 26.
Update to new upstream release 1.2.0 Security fix for CVE-2016-7069 and CVE-2017-7557

Summary

dnsdist is a highly DNS-, DoS- and abuse-aware loadbalancer. Its goal in life

is to route traffic to the best server, delivering top performance to

legitimate users while shunting or blocking abusive traffic.

Update to new upstream release 1.2.0 Security fix for CVE-2016-7069 and

CVE-2017-7557

[ 1 ] Bug #1483870 - CVE-2016-7069 dnsdist: Crafted backend responses can cause a denial of service

https://bugzilla.redhat.com/show_bug.cgi?id=1483870

[ 2 ] Bug #1483867 - CVE-2017-7557 dnsdist: Alteration of ACLs via API authentication bypass

https://bugzilla.redhat.com/show_bug.cgi?id=1483867

su -c 'dnf upgrade dnsdist' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 1.2.0
Release: 1.fc26
Summary: Highly DNS-, DoS- and abuse-aware loadbalancer

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here