Oval Definition:oval:org.mitre.oval:def:7931
Revision Date:2014-06-23Version:18
Title:DSA-1628 pdns -- DNS response spoofing
Description:Brian Dowling discovered that the PowerDNS authoritative name server does not respond to DNS queries which contain certain characters, increasing the risk of successful DNS spoofing (CVE-2008-3337). This update changes PowerDNS to respond with SERVFAIL responses instead.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-3337
DSA-1628
Platform(s):Debian GNU/Linux 4.0
Product(s):pdns
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • pdns-doc is earlier than 2.9.20-8+etch1
  • OR pdns is earlier than 2.9.20-8+etch1
  • OR pdns-backend-pipe is earlier than 2.9.20-8+etch1
  • OR pdns-server is earlier than 2.9.20-8+etch1
  • OR pdns-backend-sqlite is earlier than 2.9.20-8+etch1
  • OR pdns-backend-ldap is earlier than 2.9.20-8+etch1
  • OR pdns-backend-geo is earlier than 2.9.20-8+etch1
  • OR pdns-backend-mysql is earlier than 2.9.20-8+etch1
  • OR pdns-backend-pgsql is earlier than 2.9.20-8+etch1
  • BACK