A vulnerability was discovered in NSD which could allow a local attacker to cause a Denial of Service condition.
|Package||net-dns/nsd on all architectures|
|Affected versions||< 4.3.4|
|Unaffected versions||>= 4.3.4|
An authoritative only, high performance, open source name server
A local vulnerability was discovered that would allow for a local symlink attack due to how NSD handles PID files.
A local attacker could cause a Denial of Service condition.
There is no known workaround at this time.
All NSD users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-dns/nsd-4.3.4"
January 29, 2021
January 29, 2021: 1