Robert Edmonds wrote:
> Jan Včelák wrote:
>> - The 1.6 packet processing code contained the same issue in NAPTR parsing
>>   which was present in the 2.0. However, existing code paths to its 
>> occurrence
>>   were different. We are not aware of any possibility to remotely crash the
>>   server daemon at the moment. 
> 
> Do you know if this vulnerability affects versions prior to Knot DNS
> 1.6?

Hello Robert.

The problematic code was introduced in the 1.6.0-rc1 release. So the
older versions are probably not affected — but there might be another
problme.

(If you are using anything older than 1.6, I can just suggest you to
upgrade. We don't perform any testing on the old releases. And we don't
backport any fixes we accidentally find in the current code.)

Cheers,

Jan
_______________________________________________
knot-dns-users mailing list
[email protected]
https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users

Reply via email to