{"id":"openSUSE-SU-2024:0114-1","summary":"Security update for pdns-recursor","details":"This update for pdns-recursor fixes the following issues:\n\n- update to 4.8.8:\n  * fixes a case when a crafted responses can lead to a denial of\n    service in Recursor if recursive forwarding is configured\n    (boo#1223262, CVE-2024-25583)\n\n- changes in 4.8.7:\n  * If serving stale, wipe CNAME records from cache when we get\n    a NODATA negative response for them\n  * Fix the zoneToCache regression introduced by last security\n    update\n","modified":"2026-03-11T07:33:32.231999Z","published":"2024-04-29T06:38:41Z","related":["CVE-2024-25583"],"upstream":["CVE-2024-25583"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZZH2ONXJKWNVDG6IH66D5CLFDU6CHDXI/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1223262"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-25583"}],"affected":[{"package":{"name":"pdns-recursor","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/pdns-recursor&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.8.8-bp155.2.6.1"}]}],"ecosystem_specific":{"binaries":[{"pdns-recursor":"4.8.8-bp155.2.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0114-1.json"}},{"package":{"name":"pdns-recursor","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/pdns-recursor&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.8.8-bp155.2.6.1"}]}],"ecosystem_specific":{"binaries":[{"pdns-recursor":"4.8.8-bp155.2.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0114-1.json"}}],"schema_version":"1.7.5"}