Summary: | <net-dns/unbound-1.4.3 - remote DoS (CVE-2010-0969) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Doktor Notor <notordoktor> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | matsuu |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.unbound.net/download.html | ||
Whiteboard: | B3 [glsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 299016 | ||
Bug Blocks: |
Description
Doktor Notor
2010-03-12 11:45:02 UTC
1.4.3 in cvs now. Is this ok to go stable? sorry, please mark stable =net-dns/unbound-1.4.3 wdiff is missing for tests. (In reply to comment #4) > wdiff is missing for tests. I added it. x86 stable amd64 stable, all arches done. Vote: yes CVE-2010-0969 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0969): Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors. YES too, request filed. This issue was resolved and addressed in GLSA 201110-12 at http://security.gentoo.org/glsa/glsa-201110-12.xml by GLSA coordinator Tobias Heinlein (keytoaster). |