Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE: 2018:4062-1 Moderate: pdns-recursor Denial Of Service Fixes

opensuse
Calendar Grey December 10, 2018
Dist Opensuse Esm H88
A significant openSUSE upgrade addresses four security vulnerabilities found in pdns-recursor. Detailed installation steps are provided within.
An update that solves four vulnerabilities and has one errata is now available.

Description

This update for pdns-recursor to version 4.1.8 fixes the following issues:

Security issues fixed:

- CVE-2018-10851: Fixed denial of service via crafted zone record or

crafted answer (bsc#1114157).

- CVE-2018-14644: Fixed denial of service via crafted query for meta-types

(bsc#1114170).

- CVE-2018-14626: Fixed packet cache pollution via crafted query

(bsc#1114169).

- CVE-2018-16855: Fixed case where a crafted query could cause a denial of

service (bsc#1116592)

Non-security issues fixed:

- Fixed build failure with Boost 1.67.0 (bsc#1089814).

- Revert ‘Keep the EDNS status of a server on FormErr with EDNS’

- Refuse queries for all meta-types

For more details about this update, refer to:

https://blog.powerdns.com/2018/11/26/powerdns-recursor-4-1-8-released

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2018-1524=1

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64):

pdns-recursor-4.1.8-13.1

pdns-recursor-debuginfo-4.1.8-13.1

pdns-recursor-debugsource-4.1.8-13.1

References

https://www.suse.com/security/cve/CVE-2018-10851.html

https://www.suse.com/security/cve/CVE-2018-14626.html

https://www.suse.com/security/cve/CVE-2018-14644.html

https://www.suse.com/security/cve/CVE-2018-16855.html

https://bugzilla.suse.com/1089814

https://bugzilla.suse.com/1114157

https://bugzilla.suse.com/1114169

https://bugzilla.suse.com/1114170

https://bugzilla.suse.com/1116592

--

Announcement ID: openSUSE-SU-2018:4062-1
Rating: moderate
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here