A vulnerability was discovered in NSD which could allow a local attacker to cause a Denial of Service condition.
Package | net-dns/nsd on all architectures |
---|---|
Affected versions | < 4.3.4 |
Unaffected versions | >= 4.3.4 |
An authoritative only, high performance, open source name server
A local vulnerability was discovered that would allow for a local symlink attack due to how NSD handles PID files.
A local attacker could cause a Denial of Service condition.
There is no known workaround at this time.
All NSD users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-dns/nsd-4.3.4"
Release date
January 29, 2021
Latest revision
January 29, 2021: 1
Severity
normal
Exploitable
local
Bugzilla entries