git: 91a5f545e162 - main - security/vuxml: Document dns/powerdns CVE-2021-36754

Sergey A. Osokin osa at freebsd.org
Thu Jul 29 09:54:32 UTC 2021


Thank you so much, Li-Wen!

On Tue, Jul 27, 2021 at 09:01:13AM +0000, Li-Wen Hsu wrote:
> The branch main has been updated by lwhsu:
> 
> URL: https://cgit.FreeBSD.org/ports/commit/?id=91a5f545e16283e3fcc682676521a40036cc8691
> 
> commit 91a5f545e16283e3fcc682676521a40036cc8691
> Author:     rob2g2 <rob2g2-freebsd at bitbert.com>
> AuthorDate: 2021-07-27 08:48:53 +0000
> Commit:     Li-Wen Hsu <lwhsu at FreeBSD.org>
> CommitDate: 2021-07-27 09:00:51 +0000
> 
>     security/vuxml: Document dns/powerdns CVE-2021-36754
>     
>     PR:             257435
> ---
>  security/vuxml/vuln-2021.xml | 26 ++++++++++++++++++++++++++
>  1 file changed, 26 insertions(+)
> 
> diff --git a/security/vuxml/vuln-2021.xml b/security/vuxml/vuln-2021.xml
> index b10f789df286..d9889781f7f0 100644
> --- a/security/vuxml/vuln-2021.xml
> +++ b/security/vuxml/vuln-2021.xml
> @@ -1,3 +1,29 @@
> +  <vuln vid="ce79167f-ee1c-11eb-9785-b42e99a1b9c3">
> +    <topic>powerdns -- remotely triggered crash</topic>
> +    <affects>
> +      <package>
> +	<name>powerdns</name>
> +	<range><eq>4.5.0</eq></range>
> +      </package>
> +    </affects>
> +    <description>
> +      <body xmlns="http://www.w3.org/1999/xhtml">
> +	<p>powerdns reports:</p>
> +	<blockquote cite="https://www.powerdns.com/news.html#20210726">
> +	  <p>PowerDNS Security Advisory 2021-01: Specific query crashes Authoritative Server</p>
> +	</blockquote>
> +      </body>
> +    </description>
> +    <references>
> +      <cvename>CVE-2021-36754</cvename>
> +      <url>https://blog.powerdns.com/2021/07/26/security-advisory-2021-01-for-powerdns-authoritative-server-4-5-0/</url>
> +    </references>
> +    <dates>
> +      <discovery>2021-07-26</discovery>
> +      <entry>2021-07-27</entry>
> +    </dates>
> +  </vuln>
> +
>    <vuln vid="cc553d79-e1f0-4b94-89f2-bacad42ee826">
>      <topic>mosquitto -- NULL pointer dereference</topic>
>      <affects>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 789 bytes
Desc: not available
URL: <http://lists.freebsd.org/pipermail/dev-commits-ports-all/attachments/20210729/ce915fa3/attachment.sig>


More information about the dev-commits-ports-all mailing list