Lucene search

K
osvGoogleOSV:DSA-1628-1
HistoryAug 10, 2008 - 12:00 a.m.

pdns - DNS spoofing

2008-08-1000:00:00
Google
osv.dev
21

EPSS

0.007

Percentile

79.9%

Brian Dowling discovered that the PowerDNS authoritative name server
does not respond to DNS queries which contain certain characters,
increasing the risk of successful DNS spoofing (CVE-2008-3337). This
update changes PowerDNS to respond with SERVFAIL responses instead.

For the stable distribution (etch), this problem has been fixed in version
2.9.20-8+etch1.

For the unstable distribution (sid), this problem has been fixed in
version 2.9.21.1-1.

We recommend that you upgrade your pdns package.