{"id":"openSUSE-SU-2022:10171-1","summary":"Security update for pdns-recursor","details":"This update for pdns-recursor fixes the following issues:\n\npdns-recursor was updated to 4.6.3:\n\n* fixes incomplete exception handling related to protobuf message generation (boo#1202664, CVE-2022-37428)\n\npdns-recursor was updated to 4.6.2:\n\n* Reject non-apex NSEC(3)s that have both the NS and SOA bits set\n* A CNAME answer on DS query should abort DS retrieval\n* Allow disabling of processing the root hints\n* If we get NODATA on an AAAA in followCNAMERecords, try native dns64\n","modified":"2026-03-11T07:33:35.250229Z","published":"2022-10-30T15:07:10Z","related":["CVE-2022-37428"],"upstream":["CVE-2022-37428"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QTTGUFMAXOAIF5ITDWH77TARHQP4EO3F/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37428"}],"affected":[{"package":{"name":"pdns-recursor","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/pdns-recursor&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.3-bp154.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"pdns-recursor":"4.6.3-bp154.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10171-1.json"}},{"package":{"name":"pdns-recursor","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/pdns-recursor&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.3-bp154.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"pdns-recursor":"4.6.3-bp154.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10171-1.json"}}],"schema_version":"1.7.5"}