Security vulnerability in Posadis 0.50.4 and later
Meilof Veeningen <[email protected]> Wed, 29 Jan 2003 12:08:40 +0100
| Newsgroups | gmane.network.dns.posadis.announce |
|---|---|
| Message-ID | <[email protected]> |
From http://www.posadis.org/security/0_50_8_vuln.html:
Remote vulnerability in Posadis 0.50.x
Products affected
* Posadis DNS server, all platforms, versions 0.50.4 through 0.50.8
Not affected
* Posadis DNS server, Milestone 5 and earlier; versions 0.50.9 and
later, or version 0.50.8 with the bugfix patch applied.
* Poslib DNS library and applications using it, such as the Simple
Authoritive Name Server and Pos6, the unstable 0.60.x series of
Posadis.
Details
Posadis versions 0.50.4 through 0.50.8 contain a bug, causing them not
to properly check whether specific DNS messages contain a question
section. Thus, Posadis might try to read from a NULL memory location.
This bug, which was discovered in an internal test, allows any person to
crash the DNS server by sending a malformed packet to it. It is not
known whether this bug can be used to execute arbitrary code on the server.
Solution
Users of Posadis 0.50.8 and earlier should upgrade as soon as possible.
I will release a new Posadis version, 0.50.9, as soon as possible, but
for now, try one of the following:
* Download a new source tarball: posadis-0.50.8a.tar.gz
<http://www.posadis.org/files/posadis-0.50.8a.tar.gz> (md5sum
a98f3075d425eb8d87685da13c2d01a6)
* Download a patch from the Posadis 0.50.8 sources: pos-0.50.8-fix
<http://www.posadis.org/files/pos-0.50.8-fix> (md5sum
f38026481ee946cc9755b742211b3582)
* Download a new Posadis binary for Linux: posadis-0.50.8-fixed
<http://www.posadis.org/files/posadis-0.50.8-fixed> (md5sum
d3d92e7871e532a5cee6ecb33136bfa6)
A Windows binary will follow shortly.
-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com