LWN.net Logo

pdnsb: denial of service

Package(s):pdnsd CVE #(s):CVE-2008-4194
Created:January 12, 2009 Updated:January 14, 2009
Description:

From the Gentoo advisory:

The p_exec_query() function in src/dns_query.c does not properly handle many entries in the answer section of a DNS reply, related to a "dangling pointer bug" (CVE-2008-4194).

[This] can be exploited by enticing pdnsd to send a query to a malicious DNS server, or using the port randomization weakness, and might lead to a Denial of Service.

Alerts:
Gentoo 200901-03 2009-01-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds