PowerDNS: Denial of Service vulnerability A vulnerability in PowerDNS could lead to a temporary Denial of Service. PowerDNS February 13, 2005 May 22, 2006: 02 80713 remote 2.9.17 2.9.17

The PowerDNS Nameserver is an authoritative-only nameserver which uses a flexible backend architecture.

A vulnerability has been reported in the DNSPacket::expand method of dnspacket.cc.

An attacker could cause a temporary Denial of Service by sending a random stream of bytes to the PowerDNS Daemon.

There is no known workaround at this time.

All PowerDNS users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-dns/pdns-2.9.17"
PowerDNS Release Notes PowerDNS Ticket #21 CVE-2005-0428 vorlon078 vorlon078