An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Such a user could be a customer inserting data via a control panel, or somebody with access to the REST API. Crafted records cannot be inserted via AXFR (CVE-2020-17482). . MGASA-2020-0375 - Updated pdns packages fix security vulnerability Publication date: 27 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0375.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-17482 An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Such a user could be a customer inserting data via a control panel, or somebody with access to the REST API. Crafted records cannot be inserted via AXFR (CVE-2020-17482). The pdns package has been updated to versoin 4.1.14, fixing this issue and several other bugs. See the upstream changelog for details. References: - https://bugs.mageia.org/show_bug.cgi?id=27310 - https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.14 - https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-05.html - https://www.cve.org/CVERecord?id=CVE-2020-17482 SRPMS: - 7/core/pdns-4.1.14-1.mga7 . Mageia 7 pdns patch addresses memory leak for trusted users; bolster system protection.. PowerDNS Security, Memory Leak Issue, Mageia Updates, pdns Vulnerability. . LinuxSecurity.com Team
- Update to 3.4.7 - CVE-2015-5311 Release notes: . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-a3965fd800 2015-11-20 19:00:55.798647 -------------------------------------------------------------------------------- Name : pdns Product : Fedora 21 Version : 3.4.7 Release : 1.fc21 URL : https://www.powerdns.com/ Summary : A modern, advanced and high performance authoritative-only nameserver Description : The PowerDNS Nameserver is a modern, advanced and high performance authoritative-only nameserver. It is written from scratch and conforms to all relevant DNS standards documents. Furthermore, PowerDNS interfaces with almost any database. -------------------------------------------------------------------------------- Update Information: - Update to 3.4.7 - CVE-2015-5311 Release notes: -------------------------------------------------------------------------------- References: [ 1 ] Bug #1279377 - CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS) https://bugzilla.redhat.com/show_bug.cgi?id=1279377 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pdns' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.