Package: pdnsd
Severity: serious
Tags: security

CVE-2006-2076: "Memory leak in Paul Rombouts pdnsd before 1.2.4 allows
remote attackers to cause a denial of service (memory consumption) via a
DNS query with an unsupported (1) QTYPE or (2) QCLASS, as demonstrated
by the OUSPG PROTOS DNS test suite."

CVE-2006-2077: "Buffer overflow in Paul Rombouts pdnsd before 1.2.4 has
unknown impact and attack vectors. NOTE: this issue might be related to
the OUSPG PROTOS DNS test suite."

This issue appears to also affect sarge's pdnsd.

Please mention the CVEs in your changelog.

Thanks,

Alec


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to