Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 4424-1] pdns security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 4424-1] pdns security update


Chronologisch Thread 
  • From: Sebastien Delafond <seb AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 4424-1] pdns security update
  • Date: Thu, 04 Apr 2019 16:11:10 +0000
  • List-archive: https://lists.debian.org/msgid-search/E1hC4xK-0004Zy-Dh AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-return-path: <seb AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Thu, 4 Apr 2019 16:11:24 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <mnJNDj_yLhE.A.6SE.syipcB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4424-1 security AT debian.org
https://www.debian.org/security/ Sebastien Delafond
April 04, 2019 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : pdns
CVE ID : CVE-2019-3871
Debian Bug : 924966

Adam Dobrawy, Frederico Silva and Gregory Brzeski from HyperOne.com
discovered that pdns, an authoritative DNS server, did not properly
validate user-supplied data when building a HTTP request from a DNS
query in the HTTP Connector of the Remote backend. This would allow a
remote user to cause either a denial-of-service, or information
disclosure.

For the stable distribution (stretch), this problem has been fixed in
version 4.0.3-1+deb9u4.

We recommend that you upgrade your pdns packages.

For the detailed security status of pdns please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pdns

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlymLHkACgkQEL6Jg/PV
nWTsFQf/RvbsyjaPK20oiJxitB+O3GFU2ucUrmnjQ62lJqhDcoK/rnSpRAISvTKA
TjnbAu59/RcwnDzJMTInYrdeSq1r2sV528xV8DzpYVW21xCGGcSHA4cvWL5OVG3z
gnc/9TfkxWQkVy9o+rQukko7o2sU0vI6JUgxbA9llAhoxcII5+TmwLNEDQTL8gi4
1ljyIhTJnRMx5Uhtljp2Cr/uqZiJQTsSxqMuF+XIC62o5kSK2wCeuoRhwvWJHn4R
Xvt5ENd6rnWnuVjazG0eSAyfasNXepYmtED/crjITS2PxhV07UJqJHvxyov9QyWD
ZsnS4+Q5jwamwxGyMMtmMaiRn9Dr7g==
=Ieqy
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 4424-1] pdns security update, Sebastien Delafond, 04.04.2019

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang