SUSE-SU-2023:2777-1

    Dashboard / Vulnerabilities / SUSE-SU-2023:2777-1

    SUSE-SU-2023:2777-1

    Published: 4 Jul 2023Last Modified: 4 Feb 2026

    Summary: Security update for dnsdist

    Details: This update for dnsdist fixes the following issues: - Implements package 'dnsdist' with version 1.8.0 in SLE15. (jsc#PED-3402) - Downstream DNS resolver configuration should be chosen by the admin - Security fix: fixes a possible record smugging with a crafted DNS query with trailing data (CVE-2018-14663, bsc#1114511) - Security fix: There is an issue that can lead to a denial of service on 32-bit if a backend sends crafted answers. (CVE-2016-7069, bsc#1054799) - Security fix: Alteration of dnsdist's ACL if the API is enabled, writable and an authenticated user is tricked into visiting a crafted website. (CVE-2017-7557, bsc#1054799) - SNMP support, exporting statistics and sending traps - Preventing the packet cache from ageing responses when deployed in - Various DNSCrypt-related fixes and improvements, including automatic key rotation

    Affected packages

    Package

    Name: dnsdist

    Purl: pkg:rpm/suse/dnsdist&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSS

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.8.0-150100.3.5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High