it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5851-1] pdns-recursor security update
- Date: Tue, 28 Jan 2025 19:17:33 +0000
- Authentication-results: lists.piratenpartei.de; dkim=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/Z5ktTXyHc4BThu4v AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=9XUO4oyztQ4mlYXuLz1CAbe8qck1bxW2evuMOzHAtQE=; b=Rj nlk0Ac7TxnnKadQLbAW/cFZC00tny6rrOq7YmN9e9G4EpEHftqQpNGi6i5VpKrfxxW24mF51PtMAr 7PGkvUHIvmvOymHOuUzyerC7p7r9vZCAXAArmzKVGEmB0ouYYYjYFatc3eiO9yF3zwB9GPkZCW+qw 5A6VJbTwnwiCUzZqdVlI1UySHGPYfa2LeLgbULNU4uffJ0cmYVQT2AHNuzkdoC8+Jzp45kEzGgVKI vdepnWKUfCPW7Vgy70IgE63BuTK2NF63fLW008V5zwAmFDMJiGHxKntVPP0lDFYfMlP/Ot5EfEbRo J6h7fY2/kl6jnWe6WfEXYZNOEFKC5M3Q==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Tue, 28 Jan 2025 19:18:01 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <PM5B_C3ZmbP.A.J4bH.p1SmnB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5852-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
January 28, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : pdns-recursor
CVE ID : CVE-2024-25590
Toshifumi Sakaguchi discovered that too permissive parsing of some
resource record sets in the zone file parsing of PDNS Recursor could
result in denial of service.
For the stable distribution (bookworm), this problem has been fixed in
version 4.8.8-1+deb12u1.
We recommend that you upgrade your pdns-recursor packages.
For the detailed security status of pdns-recursor please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pdns-recursor
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmeZLQcACgkQEMKTtsN8
TjbaMg/+OoHwHXhagcBD1Fo7Ey9JcHTBW7UnraBYhm/dkZQGQmcWNkd31eyod6S+
N+4qnsFkHLpoVET9yUxQ2S7ia3rY0OOE9Hi0raOI7Pm/ABJrDs2kwdolvzt3RiYV
k4oQEwQ/OJF/cxlza3BN+QxF1JxWtvwXEf2m7ILCvwJ7jU5/N2iqdaj3yPC+GTyW
ynjjbhW0fXzGxKw3LFrLanYGfBjbzEyD6fPnYT/E1G40dFOSYuMaGkC9ETzWk+dZ
uFhEFHHQPdnqCi7PRH0Jud6626s1bajwVsNu1HldrKdq8rbiLudycy+PaO+QbuZ9
wtsyLxFm8VVQZqdQPXbhCCyRiPfrNxHMCeszXoLkyF6PZCxuMjw1Py2GjYM4jNVu
EGTQs8VfQN5qLCzpfIdV/ghXUq7V86IagF8Wvl++451WivFGWBJmWqzz80GR2ycQ
pq0BWN7IYzZVhrsvj8qbCSi4anN2Mu82IewldnE8KX8HmODadASZNjlmHEqO1OxN
vsXkasMb5sQotXO1LdWkVXJ0VToILozalNsmxC+yMb4w6bjfwEFBB7REGAyLVYVb
fCPb2tvRI5wNbfSNVWWpsC5FOkEseQDcQ+0p0hecPHPBXH3CNsmes8DYRJtQF0NA
eYJG9H3GhYuDa+dcS6mnE+2WXHCJX7yBR0J4gRRIWs3F51V7BdA=
=PVYB
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5851-1] pdns-recursor security update, Moritz Muehlenhoff, 28.01.2025
Archiv bereitgestellt durch MHonArc 2.6.19+.