Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2018:1660-1 Moderate Risk for pdns Stack Overflow Issue

suse
Calendar Grey June 12, 2018
Scroller Suse
Recent patch for pdns tackles a significant vulnerability: stack overflow threat posed by specially crafted PCAP files affecting SUSE OpenStack Cloud.
An update that fixes one vulnerability is now available

Summary

This update for pdns fixes the following issues: Security issues fixed: - CVE-2018-1046: Fix an issue with replaying a specially crafted PCAP file that can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution (bsc#1092540). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2018-1127=1 - HPE Helion OpenStack 8: zypper in -t patch HPE-Helion-OpenStack-8-2018-1127=1 Package List: - SUSE OpenStack Cloud 8 (x86_64): pdns-4.1.2-3.3.1 pdns-backend-mysql-4.1.2-3.3.1 pdns-backend-mysql-debuginfo-4.1.2-3.3.1

References

#1092540

Cross- CVE-2018-1046

Affected Products:

SUSE OpenStack Cloud 8

HPE Helion OpenStack 8

https://www.suse.com/security/cve/CVE-2018-1046.html

https://bugzilla.suse.com/1092540

Announcement ID: SUSE-SU-2018:1660-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.