{"id":"SUSE-SU-2023:2760-2","summary":"Security update for dnsdist","details":"This update for dnsdist fixes the following issues:\n\n\n- update to 1.8.0\n  - Implements dnsdist in SLE15 (jsc#PED-3402)\n  - Security fix: fixes a possible record smugging with a crafted DNS query with trailing data (CVE-2018-14663, bsc#1114511)\n\n- update to 1.2.0 (bsc#1054799, bsc#1054802)\n  This release also addresses two security issues of low severity, CVE-2016-7069 and CVE-2017-7557. The first issue can lead to a\n  denial of service on 32-bit if a backend sends crafted answers,\n  and the second to an alteration of dnsdist’s ACL if the API is\n  enabled, writable and an authenticated user is tricked into\n  visiting a crafted website. \n","modified":"2026-03-11T07:24:19.983441Z","published":"2023-12-06T09:47:21Z","related":["CVE-2016-7069","CVE-2017-7557","CVE-2018-14663"],"upstream":["CVE-2016-7069","CVE-2017-7557","CVE-2018-14663"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232760-2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1054799"},{"type":"REPORT","url":"https://bugzilla.suse.com/1054802"},{"type":"REPORT","url":"https://bugzilla.suse.com/1114511"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7069"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7557"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14663"}],"affected":[{"package":{"name":"dnsdist","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/dnsdist&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0-150400.9.3.1"}]}],"ecosystem_specific":{"binaries":[{"dnsdist":"1.8.0-150400.9.3.1","libluajit-5_1-2":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2760-2.json"}},{"package":{"name":"luajit","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/luajit&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"}]}],"ecosystem_specific":{"binaries":[{"libluajit-5_1-2":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","dnsdist":"1.8.0-150400.9.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2760-2.json"}},{"package":{"name":"dnsdist","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0-150400.9.3.1"}]}],"ecosystem_specific":{"binaries":[{"libluajit-5_1-2-32bit":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","libluajit-5_1-2":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","luajit-devel":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","luajit":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","dnsdist":"1.8.0-150400.9.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2760-2.json"}},{"package":{"name":"luajit","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/luajit&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"}]}],"ecosystem_specific":{"binaries":[{"dnsdist":"1.8.0-150400.9.3.1","libluajit-5_1-2-32bit":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","libluajit-5_1-2":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","luajit-devel":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","luajit":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2760-2.json"}},{"package":{"name":"dnsdist","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0-150400.9.3.1"}]}],"ecosystem_specific":{"binaries":[{"dnsdist":"1.8.0-150400.9.3.1","libluajit-5_1-2-32bit":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","libluajit-5_1-2":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","luajit-devel":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","luajit":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2760-2.json"}},{"package":{"name":"luajit","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/luajit&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"}]}],"ecosystem_specific":{"binaries":[{"luajit":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","dnsdist":"1.8.0-150400.9.3.1","libluajit-5_1-2-32bit":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","libluajit-5_1-2":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1","luajit-devel":"2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2760-2.json"}}],"schema_version":"1.7.5"}