python-dns-2.6.1-3.el9
エラータID: AXSA:2024-9165:02
The python-dns package contains the dnslib module that implements a DNS client and additional modules that define certain symbolic constants used by DNS, such as dnstype, dnsclass and dnsopcode.
Security Fix(es):
* dnspython: denial of service in stub resolver (CVE-2023-29483)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the MIRACLE LINUX 9.5 Release Notes linked from the References section.
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
Update packages.
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
N/A
SRPMS
- python-dns-2.6.1-3.el9.src.rpm
MD5: bcd7144286faac86f111fd9dfa971692
SHA-256: a61cbfd8b43bfd199fc64a44e14f6f4c11ff2b6b5e598bbc1d3d994ba2dce2f7
Size: 382.81 kB
Asianux Server 9 for x86_64
- python3-dns-2.6.1-3.el9.noarch.rpm
MD5: d682296658d0b8b7d5a48dc8cb3389f2
SHA-256: 5eced976a61bdb981bd5edf1de78825a7abdf48bcda06573ee71f5af0cd8ac49
Size: 506.73 kB