The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Vulnerability of PowerDNS: denial of service via Zone Record

Synthesis of the vulnerability

An attacker can generate a fatal error via Zone Record of PowerDNS, in order to trigger a denial of service.
Severity of this threat: 2/4.
Creation date: 16/11/2018.
Références of this weakness: CVE-2018-10851, FEDORA-2018-2ff7cdbb7b, FEDORA-2018-5a1e2759aa, FEDORA-2018-85fc964de8, openSUSE-SU-2018:4062-1, openSUSE-SU-2018:4073-1, openSUSE-SU-2018:4151-1, openSUSE-SU-2018:4152-1, openSUSE-SU-2018:4156-1, openSUSE-SU-2018:4175-1, openSUSE-SU-2018:4177-1, openSUSE-SU-2018:4262-1, VIGILANCE-VUL-27800.

Description of the vulnerability

An attacker can generate a fatal error via Zone Record of PowerDNS, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

This security bulletin impacts software or systems such as Fedora, openSUSE Leap, SUSE Linux Enterprise Desktop, SLES.

Our Vigil@nce team determined that the severity of this cybersecurity announce is medium.

The trust level is of type confirmed by the editor, with an origin of intranet server.

An attacker with a expert ability can exploit this vulnerability alert.

Solutions for this threat

Fedora: new pdns packages.
New packages are available:
  Fedora 27: pdns 4.1.5-1.fc27
  Fedora 28: pdns 4.1.5-1.fc28
  Fedora 29: pdns 4.1.5-1.fc29

openSUSE Leap 15.0: new pdns packages.
New packages are available:
  openSUSE Leap 15.0: pdns 4.1.2-lp150.3.6.1

openSUSE Leap 15.0: new pdns-recursor packages.
New packages are available:
  openSUSE Leap 15.0: pdns-recursor 4.1.2-lp150.2.3.1

openSUSE Leap 42.3: new pdns packages.
New packages are available:
  openSUSE Leap 42.3: pdns 4.0.3-15.2

openSUSE Leap 42.3: new pdns-recursor packages.
New packages are available:
  openSUSE Leap 42.3: pdns-recursor 4.0.5-9.1

SUSE LE 12: new pdns packages.
New packages are available:
  SUSE LE 12 RTM-SP3: pdns 4.1.5-14.1

SUSE LE 12: new pdns-recursor packages.
New packages are available:
  SUSE LE 12 RTM-SP3: pdns-recursor 4.1.8-13.1

SUSE LE 15: new pdns packages.
New packages are available:
  SUSE LE 15 RTM: pdns 4.1.2-bp150.2.3.1

SUSE LE 15: new pdns-recursor packages.
New packages are available:
  SUSE LE 15 RTM: pdns-recursor 4.1.2-bp150.2.3.1
Full Vigil@nce bulletin... (Free trial)

Computer vulnerabilities tracking service

Vigil@nce provides an applications vulnerabilities alert. The Vigil@nce vulnerability database contains several thousand vulnerabilities.