SUSE-SU-2023:2760-1

Source
https://www.suse.com/support/update/announcement/2023/suse-su-20232760-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2760-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2023:2760-1
Related
Published
2023-12-06T09:47:21Z
Modified
2023-12-06T09:47:21Z
Summary
Security update for dnsdist
Details

This update for dnsdist fixes the following issues:

  • update to 1.8.0

    • Implements dnsdist in SLE15 (jsc#PED-3402)
    • Security fix: fixes a possible record smugging with a crafted DNS query with trailing data (CVE-2018-14663, bsc#1114511)
  • update to 1.2.0 (bsc#1054799, bsc#1054802) This release also addresses two security issues of low severity, CVE-2016-7069 and CVE-2017-7557. The first issue can lead to a denial of service on 32-bit if a backend sends crafted answers, and the second to an alteration of dnsdist’s ACL if the API is enabled, writable and an authenticated user is tricked into visiting a crafted website.

References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP4 / dnsdist

Package

Name
dnsdist
Purl
pkg:rpm/suse/dnsdist&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0-150400.9.3.1

Ecosystem specific

{
    "binaries": [
        {
            "dnsdist": "1.8.0-150400.9.3.1",
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

SUSE:Linux Enterprise Module for Basesystem 15 SP4 / luajit

Package

Name
luajit
Purl
pkg:rpm/suse/luajit&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1

Ecosystem specific

{
    "binaries": [
        {
            "dnsdist": "1.8.0-150400.9.3.1",
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

SUSE:Linux Enterprise Module for Package Hub 15 SP4 / luajit

Package

Name
luajit
Purl
pkg:rpm/suse/luajit&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1

Ecosystem specific

{
    "binaries": [
        {
            "luajit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

SUSE:Linux Enterprise Module for Package Hub 15 SP5 / luajit

Package

Name
luajit
Purl
pkg:rpm/suse/luajit&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1

Ecosystem specific

{
    "binaries": [
        {
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "luajit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

SUSE:Linux Enterprise Workstation Extension 15 SP4 / luajit

Package

Name
luajit
Purl
pkg:rpm/suse/luajit&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1

Ecosystem specific

{
    "binaries": [
        {
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

SUSE:Linux Enterprise Workstation Extension 15 SP5 / luajit

Package

Name
luajit
Purl
pkg:rpm/suse/luajit&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1

Ecosystem specific

{
    "binaries": [
        {
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

openSUSE:Leap 15.4 / dnsdist

Package

Name
dnsdist
Purl
pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2015.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0-150400.9.3.1

Ecosystem specific

{
    "binaries": [
        {
            "luajit-devel": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "dnsdist": "1.8.0-150400.9.3.1",
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "libluajit-5_1-2-32bit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "luajit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

openSUSE:Leap 15.4 / luajit

Package

Name
luajit
Purl
pkg:rpm/opensuse/luajit&distro=openSUSE%20Leap%2015.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1

Ecosystem specific

{
    "binaries": [
        {
            "luajit-devel": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "dnsdist": "1.8.0-150400.9.3.1",
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "libluajit-5_1-2-32bit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "luajit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

openSUSE:Leap 15.5 / dnsdist

Package

Name
dnsdist
Purl
pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2015.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0-150400.9.3.1

Ecosystem specific

{
    "binaries": [
        {
            "luajit-devel": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "dnsdist": "1.8.0-150400.9.3.1",
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "libluajit-5_1-2-32bit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "luajit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}

openSUSE:Leap 15.5 / luajit

Package

Name
luajit
Purl
pkg:rpm/opensuse/luajit&distro=openSUSE%20Leap%2015.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1

Ecosystem specific

{
    "binaries": [
        {
            "luajit-devel": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "dnsdist": "1.8.0-150400.9.3.1",
            "libluajit-5_1-2": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "libluajit-5_1-2-32bit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1",
            "luajit": "2.1.0~beta3+git.1624618403.e9577376-150400.4.2.1"
        }
    ]
}