Re: [Pdns-users] PowerDNS Security Advisory 2012-01: Denial of Service vulnerability in most versions of the PowerDNS Authoritative Server

2012-01-17 Thread Nils Breunese (Lemonbit)
Peter van Dijk wrote: On Jan 12, 2012, at 8:09 , Nick Milas wrote: I haven't been able to find 2.9.22.5 binary packages (RHEL/CENTOS 5, 64bit) on any of the repos. Could someone please provide some guidance to find these packages? They are at

Re: [Pdns-users] PowerDNS Security Advisory 2012-01: Denial of Service vulnerability in most versions of the PowerDNS Authoritative Server

2012-01-17 Thread Peter van Dijk
Hello Nils, On Jan 17, 2012, at 20:51 , Nils Breunese (Lemonbit) wrote: Peter van Dijk wrote: On Jan 12, 2012, at 8:09 , Nick Milas wrote: I haven't been able to find 2.9.22.5 binary packages (RHEL/CENTOS 5, 64bit) on any of the repos. Could someone please provide some guidance to

Re: [Pdns-users] PowerDNS Security Advisory 2012-01: Denial of Service vulnerability in most versions of the PowerDNS Authoritative Server

2012-01-15 Thread Peter van Dijk
Hello Nick, On Jan 12, 2012, at 8:09 , Nick Milas wrote: On 10/1/2012 9:04 μμ, bert hubert wrote: Tarballs and new static builds (32/64bit, RPM/DEB) of 2.9.22.5 and 3.0.1 have been uploaded to our download site. Kees Monshouwer has provided updated CentOS/RHEL packages in his repository.

[Pdns-users] PowerDNS Security Advisory 2012-01: Denial of Service vulnerability in most versions of the PowerDNS Authoritative Server

2012-01-10 Thread bert hubert
Dear PowerDNS users, It saddens us to have to release this Security Advisory, the first one since almost exactly two years ago. Updated versions of the Authoritative Server are available from http://www.powerdns.com/content/downloads.html and you will find two workarounds and a patch below. A

Re: [Pdns-users] PowerDNS Security Advisory 2012-01: Denial of Service vulnerability in most versions of the PowerDNS Authoritative Server

2012-01-10 Thread Peter van Dijk
Dear PowerDNS users, On Jan 10, 2012, at 15:01 , bert hubert wrote: |Workaround |Several, the easiest is setting: cache-ttl=0, which does have a| | |performance impact. Please see below. | Based on a detailed report from a user (thank you!) I

Re: [Pdns-users] PowerDNS Security Advisory 2012-01: Denial of Service vulnerability in most versions of the PowerDNS Authoritative Server

2012-01-10 Thread Charles Sprickman
Two quick questions for those of us not running Linux: -Are you coordinating with the FreeBSD port maintainer to get the new version pushed out? (http://www.freshports.org/dns/powerdns) -For those of us unfamiliar with iptables, can you describe in a more generic fashion what that rule is

Re: [Pdns-users] PowerDNS Security Advisory 2012-01: Denial of Service vulnerability in most versions of the PowerDNS Authoritative Server

2012-01-10 Thread Augie Schwer
On Tue, Jan 10, 2012 at 6:01 AM, bert hubert bert.hub...@netherlabs.nl wrote: To solve this issue, we recommend upgrading to the latest packages available for your system. Tarballs and new static builds (32/64bit, RPM/DEB) of 2.9.22.5 and 3.0.1 have been uploaded to our download site. Kees