Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 501686 (CVE-2014-2031)

Summary: <net-dns/maradns-{1.4.14,2.0.09}: Multiple vulnerabilities (CVE-2014-{2031,2032})
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: maintainer-needed
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://secunia.com/advisories/57033/
Whiteboard: B3 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2014-02-18 13:45:08 UTC
From ${URL} :

Description

A vulnerability has been reported in MaraDNS, which can be exploited by malicious people to cause a DoS 
(Denial of Service).

For more information:
SA57032

The vulnerability is reported in versions prior to 1.4.14 and 2.0.09.


Solution:
Update to version 1.4.14 or 2.0.09.

Original Advisory:
http://samiam.org/blog/2014-02-12.html


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Sergey Popov gentoo-dev 2014-02-26 14:15:13 UTC
+*maradns-2.0.09 (26 Feb 2014)
+*maradns-1.4.14 (26 Feb 2014)
+
+  26 Feb 2014; Sergey Popov <pinkbyte@gentoo.org> +maradns-1.4.14.ebuild,
+  +maradns-2.0.09.ebuild, +files/maradns-2.0.09-build.patch:
+  Version bump, wrt bug #501686

Arches, please test and mark stable

=net-dns/maradns-1.4.14
=net-dns/maradns-2.0.09

Target keywords: amd64 ppc x86
Comment 2 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-02-28 09:40:22 UTC
ppc stable
Comment 3 Sergey Popov gentoo-dev 2014-02-28 09:57:23 UTC
amd64/x86 stable

Old versions cleaned up

GLSA vote: no
Comment 4 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-02-28 10:08:52 UTC
GLSA vote: no.

Closing as [noglsa].