From: Josh Soref <2119212+jsoref@users.noreply.github.com> Date: Fri, 21 Feb 2025 16:08:34 +0000 (-0500) Subject: docs: Fix allow-from markup/link X-Git-Tag: dnsdist-2.0.0-alpha2~124^2~6 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=14a973de18e32bfdce1d5cb5dca8f8f66791b819;p=thirdparty%2Fpdns.git docs: Fix allow-from markup/link Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com> --- diff --git a/docs/security-advisories/powerdns-advisory-2015-01.rst b/docs/security-advisories/powerdns-advisory-2015-01.rst index c6851248af..66120fd27e 100644 --- a/docs/security-advisories/powerdns-advisory-2015-01.rst +++ b/docs/security-advisories/powerdns-advisory-2015-01.rst @@ -16,10 +16,13 @@ PowerDNS Security Advisory 2015-01: Label decompression bug can cause crashes or - Solution: Upgrade to any of the non-affected versions - Workaround: Run your Recursor under a supervisor. Exposure can be limited by configuring the - ```allow-from`` <../recursor/settings.md#allow-from>`__ setting so + |allow-from|_ setting so only trusted users can query your nameserver. There is no workaround for the Authoritative server. +.. |allow-from| replace:: ``allow-from`` +.. _allow-from: :ref:`setting-allow-from` + A bug was discovered in our label decompression code, making it possible for names to refer to themselves, thus causing a loop during decompression. On some platforms, this bug can be abused to cause diff --git a/pdns/recursordist/docs/security-advisories/powerdns-advisory-2014-01.rst b/pdns/recursordist/docs/security-advisories/powerdns-advisory-2014-01.rst index ba5974a54a..d5ff1ac085 100644 --- a/pdns/recursordist/docs/security-advisories/powerdns-advisory-2014-01.rst +++ b/pdns/recursordist/docs/security-advisories/powerdns-advisory-2014-01.rst @@ -14,9 +14,12 @@ - Risk of system compromise: No - Solution: Upgrade to PowerDNS Recursor 3.6.1 - Workaround: Restrict service using - ```allow-from`` <../recursor/settings.md#allow-from>`__, install + |allow-from|_, install script that restarts PowerDNS +.. |allow-from| replace:: ``allow-from`` +.. _allow-from: :ref:`setting-allow-from` + Recently, we've discovered that PowerDNS Recursor 3.6.0 (but NOT earlier) can crash when exposed to a specific sequence of malformed packets. This sequence happened spontaneously with one of our largest