SUSE-SU-2023:2760-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2760-1
SUSE-SU-2023:2760-1
Summary: Security update for dnsdist
Details: This update for dnsdist fixes the following issues: - update to 1.8.0 - Implements dnsdist in SLE15 (jsc#PED-3402) - Security fix: fixes a possible record smugging with a crafted DNS query with trailing data (CVE-2018-14663, bsc#1114511) - update to 1.2.0 (bsc#1054799, bsc#1054802) This release also addresses two security issues of low severity, CVE-2016-7069 and CVE-2017-7557. The first issue can lead to a denial of service on 32-bit if a backend sends crafted answers, and the second to an alteration of dnsdist’s ACL if the API is enabled, writable and an authenticated user is tricked into visiting a crafted website.
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232760-1/, https://bugzilla.suse.com/1054799, https://bugzilla.suse.com/1054802, https://bugzilla.suse.com/1114511, https://www.suse.com/security/cve/CVE-2016-7069, https://www.suse.com/security/cve/CVE-2017-7557, https://www.suse.com/security/cve/CVE-2018-14663
Affected packages
Package
Name: dnsdist
Purl: pkg:rpm/suse/dnsdist&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
