From 9fa52acc748a7e0401fcbcfc20e1db595be509c3 Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Thu, 21 May 2020 23:12:40 +0200 Subject: pdns-recursor DSA --- data/CVE/list | 3 ++- data/DSA/list | 3 +++ data/dsa-needed.txt | 2 -- 3 files changed, 5 insertions(+), 3 deletions(-) diff --git a/data/CVE/list b/data/CVE/list index 31fdf756c8..007399c6ca 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -9327,9 +9327,10 @@ CVE-2020-10032 CVE-2020-10031 RESERVED CVE-2020-10030 (An issue has been found in PowerDNS Recursor 4.1.0 up to and including ...) - - pdns-recursor 4.3.1-1 + - pdns-recursor 4.3.1-1 (unimportant) NOTE: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-03.html NOTE: https://www.openwall.com/lists/oss-security/2020/05/19/3 + NOTE: Non exploitable on Linux CVE-2020-10029 (The GNU C Library (aka glibc or libc6) before 2.32 could overflow an o ...) - glibc 2.30-1 (bug #953108) [buster] - glibc (Minor issue) diff --git a/data/DSA/list b/data/DSA/list index 371a6f0996..718cfa8b5b 100644 --- a/data/DSA/list +++ b/data/DSA/list @@ -1,3 +1,6 @@ +[21 May 2020] DSA-4691-1 pdns-recursor - security update + {CVE-2020-10955 CVE-2020-12244} + [buster] - pdns-recursor 4.1.11-1+deb10u1 [20 May 2020] DSA-4690-1 dovecot - security update {CVE-2020-10957 CVE-2020-10958 CVE-2020-10967} [buster] - dovecot 1:2.3.4.1-5+deb10u2 diff --git a/data/dsa-needed.txt b/data/dsa-needed.txt index 665975c35a..1dc79b82a4 100644 --- a/data/dsa-needed.txt +++ b/data/dsa-needed.txt @@ -32,8 +32,6 @@ netqmail nss/oldstable (jmm) Roberto proposed an update including fixes for CVE-2018-12404 and CVE-2018-18508 -- -pdns-recursor (jmm) --- php7.0/oldstable -- php7.3/stable -- cgit v1.2.3