VDB
GCVE-110-MAGEIA-2015-189
GCVE-110-MAGEIA-2015-189
Advisory Published
Updated pdns and pdns-recursor packages fix security vulnerability:
A bug was discovered in the label decompression code in PowerDNS and PowerDNS
Recursor, making it possible for names to refer to themselves, thus causing a
loop during decompression. On some platforms, this bug can be abused to cause
crashes. On all platforms, this bug can be abused to cause service-affecting
CPU spikes (CVE-2015-1868).
The pdns package has been updated to version 3.3.2 and the pdns-recursor
package has been updated to version 3.6.3 to fix this issue and other bugs.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | pdns-recursor | 0 (affected), 3.6.3-1.mga4 (unaffected), 0 (affected), 3.6.3-1.mga4 (unaffected) | — |
| Mageia | pdns | 3.3.2-1.mga4 (unaffected), 0 (affected), 0 (affected), 3.3.2-1.mga4 (unaffected) | — |
| Mageia | gnutu | 0 (affected), 2.8-1.mga5 (unaffected) | — |
Aliases
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.