It was discovered that YADIFA, an authoritative DNS server, did not sufficiently check its input. This allowed a remote attacker to cause a denial-of-service by forcing the daemon to enter an infinite loop. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4001-1
20170912: YADIFA 2.2.6 --- Fixes an issue where a maliciously crafted message may block the server.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-4f2fbc84d9 2017-10-05 21:00:54.263906 --------------------------------------------------------------------------------Name : yadifa Product : Fedora 27 Version : 2.2.6 Release : 1.fc27 URL : Summary : Lightweight authoritative Name Server with DNSSEC capabilities Description : YADIFA is a name server implementation developed from scratch by .eu. It is portable across multiple operating systems and supports DNSSEC, TSIG, DNS notify, DNS update, IPv6. --------------------------------------------------------------------------------Update Information: 20170912: YADIFA 2.2.6 --- Fixes an issue where a maliciously crafted message may block the server. --------------------------------------------------------------------------------References: [ 1 ] Bug #1494005 - CVE-2017-14339 yadifa: Infinite loop due to insufficient checks in the DNS packet parser https://bugzilla.redhat.com/show_bug.cgi?id=1494005 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade yadifa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.