Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 501686 (CVE-2014-2031) - <net-dns/maradns-{1.4.14,2.0.09}: Multiple vulnerabilities (CVE-2014-{2031,2032})
Summary: <net-dns/maradns-{1.4.14,2.0.09}: Multiple vulnerabilities (CVE-2014-{2031,20...
Status: RESOLVED FIXED
Alias: CVE-2014-2031
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/57033/
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-02-18 13:45 UTC by Agostino Sarubbo
Modified: 2014-02-28 10:08 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-02-18 13:45:08 UTC
From ${URL} :

Description

A vulnerability has been reported in MaraDNS, which can be exploited by malicious people to cause a DoS 
(Denial of Service).

For more information:
SA57032

The vulnerability is reported in versions prior to 1.4.14 and 2.0.09.


Solution:
Update to version 1.4.14 or 2.0.09.

Original Advisory:
http://samiam.org/blog/2014-02-12.html


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Sergey Popov gentoo-dev 2014-02-26 14:15:13 UTC
+*maradns-2.0.09 (26 Feb 2014)
+*maradns-1.4.14 (26 Feb 2014)
+
+  26 Feb 2014; Sergey Popov <pinkbyte@gentoo.org> +maradns-1.4.14.ebuild,
+  +maradns-2.0.09.ebuild, +files/maradns-2.0.09-build.patch:
+  Version bump, wrt bug #501686

Arches, please test and mark stable

=net-dns/maradns-1.4.14
=net-dns/maradns-2.0.09

Target keywords: amd64 ppc x86
Comment 2 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-02-28 09:40:22 UTC
ppc stable
Comment 3 Sergey Popov gentoo-dev 2014-02-28 09:57:23 UTC
amd64/x86 stable

Old versions cleaned up

GLSA vote: no
Comment 4 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-02-28 10:08:52 UTC
GLSA vote: no.

Closing as [noglsa].