From $URL: An issue has been found in PowerDNS Authoritative Server when the HTTP remote backend is used in RESTful mode (without post=1 set), allowing a remote user to cause the HTTP backend to connect to an attacker-specified host instead of the configured one, via a crafted DNS query. This can be used to cause a denial of service by preventing the remote backend from getting a response, content spoofing if the attacker can time its own query so that subsequent queries will use an attacker-controlled HTTP server instead of the configured one, and possibly information disclosure if the Authoritative Server has access to internal servers. This issue has been assigned CVE-2019-3871. PowerDNS Authoritative up to and including 4.1.6 is affected.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1ae1352759b2eb9eb8fb40a99cf4095eeec713b6 commit 1ae1352759b2eb9eb8fb40a99cf4095eeec713b6 Author: Sven Wegener <swegener@gentoo.org> AuthorDate: 2019-03-18 21:49:02 +0000 Commit: Sven Wegener <swegener@gentoo.org> CommitDate: 2019-03-18 21:49:54 +0000 net-dns/pdns: Version bump, security bug #680900 Bug: https://bugs.gentoo.org/680900 Signed-off-by: Sven Wegener <swegener@gentoo.org> Package-Manager: Portage-2.3.62, Repoman-2.3.11 net-dns/pdns/Manifest | 1 + net-dns/pdns/pdns-4.1.7.ebuild | 157 +++++++++++++++++++++++++++++++++++++++++ 2 files changed, 158 insertions(+)
4.1.7 only contains the security fix over 4.1.6, which is in the tree since the end of january. so 4.1.7 should be ready for stabilization.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e3ea551322689ebe50de119d860dc5a9d9fc0d5e commit e3ea551322689ebe50de119d860dc5a9d9fc0d5e Author: Sven Wegener <swegener@gentoo.org> AuthorDate: 2019-03-19 11:37:50 +0000 Commit: Sven Wegener <swegener@gentoo.org> CommitDate: 2019-03-19 11:38:34 +0000 net-dns/pdns: Stable on amd64/x86, security bug #680900 Bug: https://bugs.gentoo.org/680900 Signed-off-by: Sven Wegener <swegener@gentoo.org> Package-Manager: Portage-2.3.62, Repoman-2.3.11 net-dns/pdns/pdns-4.1.7.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)