-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 22 Jan 2017 13:02:06 +0100 Source: pdns Binary: pdns-server pdns-server-dbg pdns-backend-pipe pdns-backend-ldap pdns-backend-geo pdns-backend-mysql pdns-backend-pgsql pdns-backend-sqlite pdns-backend-sqlite3 pdns-backend-lua Architecture: source amd64 Version: 3.1-4.1+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Debian PowerDNS Maintainers <pkg-pdns-maintain...@lists.alioth.debian.org> Changed-By: Jonas Meurer <m...@debian.org> Description: pdns-backend-geo - geo backend for PowerDNS pdns-backend-ldap - LDAP backend for PowerDNS pdns-backend-lua - lua backend for PowerDNS pdns-backend-mysql - generic MySQL backend for PowerDNS pdns-backend-pgsql - generic PostgreSQL backend for PowerDNS pdns-backend-pipe - pipe/coprocess backend for PowerDNS pdns-backend-sqlite - sqlite backend for PowerDNS pdns-backend-sqlite3 - sqlite backend for PowerDNS pdns-server - extremely powerful and versatile nameserver pdns-server-dbg - debugging symbols for PowerDNS Changes: pdns (3.1-4.1+deb7u3) wheezy-security; urgency=high . * Non-maintainer upload by the LTS Team. * Possible integer overflow when validating record size for unknown records. CVE-2016-2120: Crafted zone record can cause a denial of service * Possible denial of service (DOS) by processing queries with lots of records. CVE-2016-7068: Crafted queries can cause abnormal CPU usage * Possible denial of service (DOS) by opening many TCP connections to the webserver. CVE-2016-7072: Denial of service (DOS) via the web server * Insufficient validation of TSIG signatures CVE-2016-7073: Possible replay attack due to missing check of the TSIG time and fudge values. CVE-2016-7074: Possiblity to parse extra malicious records due to missing check that TLS record is the last one. Checksums-Sha1: deb16ce968252fdb8a4ee82b7b65ebae089e4325 2792 pdns_3.1-4.1+deb7u3.dsc 7cee235dcb0e587c5355d95370299946a8e0c9b5 57867 pdns_3.1-4.1+deb7u3.debian.tar.gz d40953444f7d064a390e5e0b62cdb8c283d6fa83 1895606 pdns-server_3.1-4.1+deb7u3_amd64.deb b83efa0bedaba854be7762212c1d11c7c5aaafb5 18943388 pdns-server-dbg_3.1-4.1+deb7u3_amd64.deb f7d75b4ac08be98146393f2ce017555ef98c8b85 86982 pdns-backend-pipe_3.1-4.1+deb7u3_amd64.deb 6f5a73daf062b68c8e1b597af5d55d6546881772 340270 pdns-backend-ldap_3.1-4.1+deb7u3_amd64.deb 6112f8ee67baa83ce663d4b9c0aa9b7c6c065ea5 108678 pdns-backend-geo_3.1-4.1+deb7u3_amd64.deb d09096ce620e7f1530d9906f88e5ead2789c56b2 74612 pdns-backend-mysql_3.1-4.1+deb7u3_amd64.deb 55d98a1f4d9ff40b8848ed51a5691b8a044d00e3 75798 pdns-backend-pgsql_3.1-4.1+deb7u3_amd64.deb faabd1a566080d305dbb81c99226194fc9db1110 63386 pdns-backend-sqlite_3.1-4.1+deb7u3_amd64.deb c2a49f9ceeeac5f90d5ad0a4eb53b9682b270be1 55850 pdns-backend-sqlite3_3.1-4.1+deb7u3_amd64.deb a4e1abc6f821cae78891eaf765d5e6b4a440c3de 125672 pdns-backend-lua_3.1-4.1+deb7u3_amd64.deb Checksums-Sha256: 2e4c3ab992e67bd79754920619650975082740cc7a54cb04eae9c2c962b8460a 2792 pdns_3.1-4.1+deb7u3.dsc e5b449c97f88d0d6bcd8b559f7d285c9b0525f83075999e938b536bf2f1a86de 57867 pdns_3.1-4.1+deb7u3.debian.tar.gz 8561efa7eb6a34e750990ca35eba2ff8ad87d7fc6326e974c2e899bac1376360 1895606 pdns-server_3.1-4.1+deb7u3_amd64.deb e96eff9fef635a6883164aeb49d33d3d3008c67537065ce148911d4d7d52ddf1 18943388 pdns-server-dbg_3.1-4.1+deb7u3_amd64.deb e451030114b09936d7925f64c140483ba3c92962c72f2fb740830fbd5ec54f94 86982 pdns-backend-pipe_3.1-4.1+deb7u3_amd64.deb 62b6104f67accd1e68a96393904a66dffd6dad99984c535e364d938c7b533ee5 340270 pdns-backend-ldap_3.1-4.1+deb7u3_amd64.deb ccb8e86d01acd33c4d05c1698ba4708653b18cdc91d0ebe8c6855c568ceba63b 108678 pdns-backend-geo_3.1-4.1+deb7u3_amd64.deb 32f9fe7f862022644c488cbd181146c9b8c459d01291dd401a6c371b5182477c 74612 pdns-backend-mysql_3.1-4.1+deb7u3_amd64.deb 9d4caf9adfedb2a91c4ca9eb00688ef29ead4bfc3aa01d0c5906db4073d1634f 75798 pdns-backend-pgsql_3.1-4.1+deb7u3_amd64.deb 1b37482eacbd4cb5e1af791d0612c35d7d7293e39f65f1275bd99defea894933 63386 pdns-backend-sqlite_3.1-4.1+deb7u3_amd64.deb 3ab94ba3f3609ddcccf7846ebacbe4c26c96ad8f8857325a672a4fd8c684fcb1 55850 pdns-backend-sqlite3_3.1-4.1+deb7u3_amd64.deb aff105fe5e18539daa06db5c682a975e48f3eddb3b2d72d9ab1824387ea4aab4 125672 pdns-backend-lua_3.1-4.1+deb7u3_amd64.deb Files: 58d77ee730ae4aaca0beaaf861fecc3e 2792 net extra pdns_3.1-4.1+deb7u3.dsc 3bcc003ab6a4e0503f92189eefb28a11 57867 net extra pdns_3.1-4.1+deb7u3.debian.tar.gz 16eaad116c46221b975d2d06a29de547 1895606 net extra pdns-server_3.1-4.1+deb7u3_amd64.deb 780506ffaf64514890a79e6f842d7d89 18943388 debug extra pdns-server-dbg_3.1-4.1+deb7u3_amd64.deb db105f2c70b57ef18c1163c73e1a214a 86982 net extra pdns-backend-pipe_3.1-4.1+deb7u3_amd64.deb 973c0dbd49d3edfa5b712af39dbc9a0f 340270 net extra pdns-backend-ldap_3.1-4.1+deb7u3_amd64.deb ad2e59ff5c3a5bd9d6d0e34bbca40202 108678 net extra pdns-backend-geo_3.1-4.1+deb7u3_amd64.deb d786bcfc0781a69b90e67ca3f0f67b89 74612 net extra pdns-backend-mysql_3.1-4.1+deb7u3_amd64.deb f4097fa313ee18610375bc02b59989b9 75798 net extra pdns-backend-pgsql_3.1-4.1+deb7u3_amd64.deb 29c36c0a4cb9f53ab5b02530da0bbee9 63386 net extra pdns-backend-sqlite_3.1-4.1+deb7u3_amd64.deb 67af8af91a245efb5f47a3952ce0760c 55850 net extra pdns-backend-sqlite3_3.1-4.1+deb7u3_amd64.deb 3886779b04c20b71035b716603913b75 125672 net extra pdns-backend-lua_3.1-4.1+deb7u3_amd64.deb
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEELIzSg9Pv30M4kOeDUmLn/0kQSf4FAliErIcACgkQUmLn/0kQ Sf7g3A/+J97cYdhPO11H64Ogfq6cFVaVfBD2spROjtgig8JNJcvf3SOsSdYVrI7R PJHPuKXRZB65EjKcs7u6iLZLa9IL5ra15FoGXXv/59Yu1GIzZJKas8tSFIPGQJ+b opaTlahPZRe/I9HgfJ3FOBFRBGjGmxU2YWZN0nQ64sdFEACzekzq2y3ZTa7SBSsl hlEoMoZ0a1MbpiRPSPFTMntWjE6ywy1DZfjbG9gZhu3bIjFpUYrJW9vWDpVpLDzJ vtRbBQuVUw58GCKMCDNUvDkLZECqk+tL3U5/jjhHmldzmo3wv5cucMdMcSb1OyzN i0ELQRAgyZogYcXcWPzrTv+MyKT++iUAOMtIBaC8CImljekZpGIGkMBFBYYm8nCv oKulkixsLzGymCdFrEngfhbd0hk0sKMa1fCHWbcP71ZZWmM2O6A4iPQASPPAoQdT rICgC7QTQbg22KH3Et40IQXJLR6KYvw7/7V13ggWATFxxi46R8+2IjA/7ABqGjzS b3wWt7QXd/Sh31NXz8zmTvCprIfknkkkWmJgE6JWo2DspjbLSpt9Y0QdeaZFEFJn zUEmo6CMwSaOoTRgwZDedOMmQCWaeAG9zL59J2QkEqpQUoF5gBOoL/JhJfLYAXHB RcbckgTFKI7V+ELPM+opE6Vl5ECFgmMd+IyFhOB7siCHUENFcbY= =EuBX -----END PGP SIGNATURE-----