Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml +++ security/vuxml/vuln.xml @@ -58,6 +58,67 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + postsrsd -- Denial of service vulnerability + + + postsrsd + 1.10 + + + + +

postsrsd developer reports:

+
+

PostSRSd could be tricked into consuming a lot of CPU time with + an SRS address that has an excessively long time stamp tag.

+
+ +
+ + CVE-2020-35573 + https://github.com/roehling/postsrsd/commit/4733fb11f6bec6524bb8518c5e1a699288c26bac + https://github.com/roehling/postsrsd/releases/tag/1.10 + + + 2020-12-12 + 2020-12-21 + +
+ + + powerdns -- Various issues in GSS-TSIG support + + + powerdns + 4.4.0 + + + + +

PowerDNS developers report:

+
+

A remote, unauthenticated attacker can trigger a race condition + leading to a crash, or possibly arbitrary code execution, by sending crafted queries with a GSS-TSIG signature.

+

A remote, unauthenticated attacker can cause a denial of service by + sending crafted queries with a GSS-TSIG signature.

+

A remote, unauthenticated attacker might be able to cause a double-free, + leading to a crash or possibly arbitrary code execution by sending crafted queries with a GSS-TSIG signature.

+
+ +
+ + CVE-2020-24696 + CVE-2020-24697 + CVE-2020-24698 + https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-06.html + + + 2020-08-27 + 2020-12-21 + +
+ vault -- User Enumeration via LDAP auth