Summary: | <net-dns/pdns-recursor-4.3.2: Access restriction bypass (CVE-2020-14196) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | swegener |
Priority: | Normal | Flags: | nattka:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-04.html | ||
Whiteboard: | C3 [noglsa cve] | ||
Package list: |
net-dns/pdns-recursor-4.3.2
|
Runtime testing required: | --- |
Description
Agostino Sarubbo
2020-07-01 13:11:01 UTC
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=67de87a7318cfb8fd5b838bbd7ab7c9a237f269f commit 67de87a7318cfb8fd5b838bbd7ab7c9a237f269f Author: Sven Wegener <swegener@gentoo.org> AuthorDate: 2020-07-01 21:52:25 +0000 Commit: Sven Wegener <swegener@gentoo.org> CommitDate: 2020-07-01 21:52:45 +0000 net-dns/pdns-recursor: Version bump, security bug #730362 Bug: https://bugs.gentoo.org/730362 Package-Manager: Portage-2.3.99, Repoman-2.3.23 Signed-off-by: Sven Wegener <swegener@gentoo.org> net-dns/pdns-recursor/Manifest | 1 + net-dns/pdns-recursor/pdns-recursor-4.3.2.ebuild | 81 ++++++++++++++++++++++++ 2 files changed, 82 insertions(+) I don't know if it will be reproducible on at/stable but I got bug 730430 from tinderbox 4.3.2 should be ready to go stable (In reply to Sven Wegener from comment #3) > 4.3.2 should be ready to go stable Thanks! x86 stable amd64 stable. Please cleanup. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e431db86a3509b26293116c304cac99aa65f0cef commit e431db86a3509b26293116c304cac99aa65f0cef Author: Sven Wegener <swegener@gentoo.org> AuthorDate: 2020-07-22 19:37:26 +0000 Commit: Sven Wegener <swegener@gentoo.org> CommitDate: 2020-07-22 19:38:01 +0000 net-dns/pdns-recursor: Cleanup Bug: https://bugs.gentoo.org/730362 Package-Manager: Portage-2.3.103, Repoman-2.3.23 Signed-off-by: Sven Wegener <swegener@gentoo.org> net-dns/pdns-recursor/Manifest | 1 - .../files/pdns-recursor-4.3.1-gcc-10.patch | 61 --------------- .../pdns-recursor/pdns-recursor-4.3.1-r1.ebuild | 86 ---------------------- net-dns/pdns-recursor/pdns-recursor-4.3.1.ebuild | 83 --------------------- 4 files changed, 231 deletions(-) NOTE: "In the default configuration the API webserver is not enabled. Only installations using a non-default value for webserver and webserver-address are affected." GLSA vote: no. Closing. |