SUSE-SU-2023:2777-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2777-1
SUSE-SU-2023:2777-1
Summary: Security update for dnsdist
Details: This update for dnsdist fixes the following issues: - Implements package 'dnsdist' with version 1.8.0 in SLE15. (jsc#PED-3402) - Downstream DNS resolver configuration should be chosen by the admin - Security fix: fixes a possible record smugging with a crafted DNS query with trailing data (CVE-2018-14663, bsc#1114511) - Security fix: There is an issue that can lead to a denial of service on 32-bit if a backend sends crafted answers. (CVE-2016-7069, bsc#1054799) - Security fix: Alteration of dnsdist's ACL if the API is enabled, writable and an authenticated user is tricked into visiting a crafted website. (CVE-2017-7557, bsc#1054799) - SNMP support, exporting statistics and sending traps - Preventing the packet cache from ageing responses when deployed in - Various DNSCrypt-related fixes and improvements, including automatic key rotation
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232777-1/, https://bugzilla.suse.com/1054799, https://bugzilla.suse.com/1054802, https://bugzilla.suse.com/1114511, https://www.suse.com/security/cve/CVE-2016-7069, https://www.suse.com/security/cve/CVE-2017-7557, https://www.suse.com/security/cve/CVE-2018-14663
Affected packages
Package
Name: dnsdist
Purl: pkg:rpm/suse/dnsdist&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSS
Affected ranges
Type: ECOSYSTEM
Events:
