
Die Debian Paketentwickler haben für den DNS Cacheresolver, ubound, ein Security Update veröffentlicht. Das Update behebt eine Denial-of-Service (DoS) Lücke, die bei ubound durch eine unzureichende Validierung von NOTIFY Queries, druchführt.
Debian unbound DSA 4544-1 Release Notes
Package : unbound CVE ID : CVE-2019-16866 Debian Bug : 941692 X41 D-Sec discovered that unbound, a validating, recursive, and caching DNS resolver, did not correctly process some NOTIFY queries. This could lead to remote denial-of-service by application crash. For the stable distribution (buster), this problem has been fixed in version 1.9.0-2+deb10u1. We recommend that you upgrade your unbound packages. For the detailed security status of unbound please refer to its security tracker page at: https://security-tracker.debian.org/tracker/unbound Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/
Quelle: https://lists.debian.org/debian-security-announce/2019/msg00196.html