Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: pdns-recursor

Found 6 matching suggestions

updated 2 days, 4 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package rotp
Crafted delegations or IP fragments can poison cached delegations in Recursor

Crafted delegations or IP fragments can poison cached delegations in Recursor.

Affected products

pdns-recursor
  • <5.2.6
  • <5.1.8
  • <5.3.1

Matching in nixpkgs

Ignored packages (1)

pkgs.rotp

Open-source modernization of the 1993 classic "Master of Orion", written in Java

Package maintainers

updated 1 day, 4 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package rotp
Crafted zones can lead to increased incoming network traffic

Crafted zones can lead to increased incoming network traffic.

Affected products

pdns-recursor
  • <5.1.10
  • <5.3.5
  • <5.2.8

Matching in nixpkgs

Ignored packages (1)

pkgs.rotp

Open-source modernization of the 1993 classic "Master of Orion", written in Java

Package maintainers

created 4 months, 3 weeks ago
A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempts

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS enabled requests and enforcing stricter validation of the received answers. The most strict mitigation done when the new setting outgoing.edns_subnet_harden (old style name edns-subnet-harden) is enabled.

Affected products

pdns-recursor
  • ==5.1.6
  • ==5.0.12
  • ==5.2.4

Matching in nixpkgs

Package maintainers

created 4 months, 3 weeks ago
A crafted zone can lead to an illegal memory access in the PowerDNS Recursor

An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patched 5.2.1 version. We would like to thank Volodymyr Ilyin for bringing this issue to our attention.

Affected products

pdns-recursor
  • ==5.2.0

Matching in nixpkgs

Package maintainers

created 4 months, 3 weeks ago
Crafted responses can lead to a denial of service due to cache inefficiencies in the Recursor

An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.

Affected products

pdns-recursor
  • <5.1.2
  • <4.9.9
  • <5.0.9

Matching in nixpkgs

Package maintainers

created 4 months, 3 weeks ago
Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configured

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.

Affected products

powerdns
  • ==4.9.4
  • ==5.0.3
  • ==4.8.7
pdns-recursor
  • ==4.9.4
  • ==5.0.3
  • ==4.8.7

Matching in nixpkgs

Package maintainers