CVE-2016-7069

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT record that has to be removed before forwarding the response to the initial client. On a 32-bit system, the pointer arithmetic used when parsing the received response to remove that record might trigger an undefined behavior leading to a crash.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2016-7069 NameCVE-2016-7069 DescriptionAn issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT record that has to be removed before forwarding the response to the initial client. On a 32-bit system, the pointer…

CVE-2016-7069

NameCVE-2016-7069
DescriptionAn issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT record that has to be removed before forwarding the response to the initial client. On a 32-bit system, the pointer arithmetic used when parsing the received response to remove that record might trigger an undefined behavior leading to a crash.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs872854

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dnsdist (PTS)bullseye1.5.1-3fixed
bookworm1.7.3-2fixed
trixie (security), trixie1.9.14-0+deb13u1fixed
forky2.0.5-1fixed
sid2.0.5-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dnsdistsourcestretch1.1.0-2+deb9u1
dnsdistsource(unstable)1.2.0-1low872854

Notes

https://dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2017-01.html
Patches: https://downloads.powerdns.com/patches/2017-01

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2017-01.htmlPatches: https://downloads.powerdns.com/patches/2017-01

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.2.0-1
sid Fixed 1.2.0-1
forky Fixed 1.2.0-1
bullseye Fixed 1.2.0-1
bookworm Fixed 1.2.0-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.