Bug 24994 - pdns new security issues CVE-2019-1016[23] and CVE-2019-10203
Summary: pdns new security issues CVE-2019-1016[23] and CVE-2019-10203
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Dimitri Jakov
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 27310
Blocks:
  Show dependency treegraph
 
Reported: 2019-06-23 18:44 CEST by David Walser
Modified: 2020-10-14 22:43 CEST (History)
3 users (show)

See Also:
Source RPM: pdns-4.1.8-1.mga7.src.rpm
CVE:
Status comment: Fixed upstream in 4.1.11


Attachments

David Walser 2019-06-23 18:45:04 CEST

Status comment: (none) => Fixed upstream in 4.1.10
Whiteboard: (none) => MGA7TOO, MGA6TOO

Comment 1 Marja Van Waes 2019-06-23 19:12:32 CEST
Assigning to our registered pdns maintainer.

Assignee: bugsquad => mitya
CC: (none) => marja11

Comment 2 Marja Van Waes 2019-06-23 19:19:14 CEST
CC'ing daviddavid, who pushed this package many times, because I haven't recently seen mitya.

CC: (none) => geiger.david68210

Comment 3 David Walser 2019-08-06 12:45:46 CEST
Upstream has issued an advisory on July 30:
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-06.html

The issue is fixed in 4.1.11, but also requires manual intervention by the sysadmin, so we'll need to include a note about that in our advisory.
https://blog.powerdns.com/2019/08/01/security-notice-for-powerdnspostgres-users/

Summary: pdns new security issues CVE-2019-1016[23] => pdns new security issues CVE-2019-1016[23] and CVE-2019-10203
Status comment: Fixed upstream in 4.1.10 => Fixed upstream in 4.1.11

Comment 4 David Walser 2019-08-11 22:36:08 CEST
Debian advisory for the first two CVEs from June 23:
https://www.debian.org/security/2019/dsa-4470
Comment 5 David Walser 2019-11-26 18:42:01 CET
openSUSE has issued an advisory for this on August 15:
https://lists.opensuse.org/opensuse-updates/2019-08/msg00090.html
Nicolas Lécureuil 2020-05-22 14:05:58 CEST

Whiteboard: MGA7TOO, MGA6TOO => MGA7TOO
CC: (none) => mageia

Comment 6 David Walser 2020-10-13 15:56:47 CEST
Fixed in:
https://advisories.mageia.org/MGASA-2020-0375.html

but that advisory needs to be updated.

Depends on: (none) => 27310
Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)

Comment 7 David Walser 2020-10-14 22:43:24 CEST
Advisory for Bug 27310 updated in SVN, so wiki advisory should get updated next time we push updates.  I've asked if the e-mail advisory can be re-sent.

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.