Bug 1540649

Summary: pdns-3.4.11 CVE-2017-15091patch required
Product: [Fedora] Fedora EPEL Reporter: Brad House <brad>
Component: pdnsAssignee: Morten Stevens <mstevens>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: epel7CC: mstevens, ruben, sander
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: pdns-3.4.11-4.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-02-17 20:20:23 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Brad House 2018-01-31 15:59:02 UTC
Description of problem:

Security scanners (e.g. Comodo's HackerGuardian) are now reporting PowerDNS 3.4.11 is susceptible to CVE-2017-15091.  After research, it appears the pdns-3.4.11-2.el7.x86_64.rpm  package does not include the necessary patch.

The patch is available here for 3.4.11:
https://downloads.powerdns.com/patches/2017-04/


Version-Release number of selected component (if applicable):
pdns-3.4.11-2

How reproducible:
N/A

Steps to Reproduce:
1. N/A
2.
3.

Actual results:
N/A

Expected results:
N/A

Additional info:
N/A

Comment 1 Fedora Update System 2018-02-01 19:06:18 UTC
pdns-3.4.11-4.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-f09712d924

Comment 2 Fedora Update System 2018-02-02 18:24:53 UTC
pdns-3.4.11-4.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-f09712d924

Comment 3 Fedora Update System 2018-02-17 20:20:23 UTC
pdns-3.4.11-4.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.