• [SECURITY] [DSA 3096-1] pdns-recursor security update

    From Sebastien Delafond@1:229/2 to All on Thu Dec 11 10:30:03 2014
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3096-1 [email protected] http://www.debian.org/security/ Sebastien Delafond December 11, 2014 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : pdns-recursor
    CVE ID : CVE-2014-8601

    Florian Maury from ANSSI discovered a flaw in pdns-recursor, a
    recursive DNS server : a remote attacker controlling
    maliciously-constructed zones or a rogue server could affect the
    performance of pdns-recursor, thus leading to resource exhaustion and
    a potential denial-of-service.

    For the stable distribution (wheezy), this problem has been fixed in
    version 3.3-3+deb7u1.

    For the upcoming stable distribution (jessie) and unstable
    distribution (sid), this problem has been fixed in version 3.6.2-1.

    We recommend that you upgrade your pdns-recursor packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.12 (GNU/Linux)

    iQEcBAEBCAAGBQJUiWGsAAoJEBC+iYPz1Z1kuFsH+weq5tKFbnPK6FBy4k6MNc1o Qe2j/ySjXZ++KDnKpZQrQevRiYO51UOa5QbIn9G5l3VtyM3VNDQqW/4jXuloRUVo VLps4UOJkGZUOwskwNSrzGsswTFCWb1CPYL+z7nd0xVWHqv/Y7XfTRYOSE/iLgHs 2sfcmcTIvr7+4VhBIxmFI3VB/4dVJ0yrAAu2wY7h1sil7Fg7gWMkt4iyxDk/Cs0C OR/GwHArzeuP+mbQCQcPgPPdS5GbNlaqs3v+hE9UHXMkaWLde9YytwVpSKu0PjKt 0Phrk8nCfaZWTideAH78YkQitji43fDsHH8nSgRbMDMxO1kpKkPIsVw90z3qoqo=
    =BNqh
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)