First published: Mon Jan 09 2012(Updated: )
<a href="http://mailman.powerdns.com/pipermail/pdns-announce/2012-January/000151.html">http://mailman.powerdns.com/pipermail/pdns-announce/2012-January/000151.html</a> says: ---- Tomorrow (Tuesday the 10th of January) at 9AM eastern time, 15:00 Central European Time, we will be releasing an important PowerDNS Security Advisory. This Advisory contains details of a Denial of Service issue within all currently used versions of the PowerDNS Authoritative Server. We will be releasing: * A configuration based workaround, which might have a performance penalty * An iptables based workaround * Versions 2.9.22.5 and 3.0.1 of the Authoritative Server As source code Packages (static 32 bit and 64 bit for Debian and RPM based Linux distributions) * A one-line patch that solves the issue for source based users * Complete details of the problem The denial of service attack is temporary in nature, but can be performed using limited resources. There is no risk of a system compromise because of this attack. This pre-announcement is made to allow operators to schedule a maintenance window to possibly upgrade or modify their systems. If you anticipate requiring help upgrading your affected systems, please contact powerdns.support at netherlabs.nl. Some more details: CVE: <a href="https://access.redhat.com/security/cve/CVE-2012-0206">CVE-2012-0206</a> Date: 10th of January 2012 Affects: Most PowerDNS Authoritative Server versions < 3.0.1 (with the exception of 2.9.22.5) Not affected: No versions of the PowerDNS Recursor ('pdns_recursor') are affected. Severity: High Impact: Temporary denial of service Exploit: Proof of concept Risk of system compromise: No Solution: Upgrade to PowerDNS Recursor 2.9.22.5 or 3.0.1 Workaround: Several ---- I think it would be good to upgrade the EPEL package to 2.9.22.5 once it is released tomorrow to protect users of the package from this vulnerability.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
PowerDNS Authoritative Server | <=2.9.22 | |
PowerDNS Authoritative Server | =3.0 | |
redhat/pdns | <2.9.22.6-1.el6 | 2.9.22.6-1.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.