VDB

GCVE-110-MAGEIA-2015-189

GCVE-110-MAGEIA-2015-189
Advisory Published
Vulnetix · Advisory published May 5, 2015
Updated pdns and pdns-recursor packages fix security vulnerability: A bug was discovered in the label decompression code in PowerDNS and PowerDNS Recursor, making it possible for names to refer to themselves, thus causing a loop during decompression. On some platforms, this bug can be abused to cause crashes. On all platforms, this bug can be abused to cause service-affecting CPU spikes (CVE-2015-1868). The pdns package has been updated to version 3.3.2 and the pdns-recursor package has been updated to version 3.6.3 to fix this issue and other bugs.

Affected Products

VendorProductVersionsPlatforms
Mageiapdns-recursor0 (affected), 3.6.3-1.mga4 (unaffected), 0 (affected), 3.6.3-1.mga4 (unaffected)
Mageiapdns3.3.2-1.mga4 (unaffected), 0 (affected), 0 (affected), 3.3.2-1.mga4 (unaffected)
Mageiagnutu0 (affected), 2.8-1.mga5 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›