SUSE-SU-2015:0979-2: moderate: Security update for dnsmasq
    sle-updates at lists.suse.com 
    sle-updates at lists.suse.com
       
    Tue Jun 23 08:08:44 MDT 2015
    
    
  
   SUSE Security Update: Security update for dnsmasq
______________________________________________________________________________
Announcement ID:    SUSE-SU-2015:0979-2
Rating:             moderate
References:         #923144 #928867 
Cross-References:   CVE-2015-3294
Affected Products:
                    SUSE OpenStack Cloud Compute 5
______________________________________________________________________________
   An update that solves one vulnerability and has one errata
   is now available.
Description:
   The DNS server dnsmasq was updated to fix one security issue and one
   non-security bug.
   The following vulnerability was fixed:
   * CVE-2015-3294: A remote unauthenticated attacker could have caused a
     denial of service (DoS) or read heap memory, potentially disclosing
     information such as performed DNS queries or encryption keys.
     (bsc#928867)
   The following bug was fixed:
   * bsc#923144: When answer to an upstream query is a CNAME pointing to an
     A/AAAA record which is present locally (/etc/hosts), allow caching when
     the upstream and local A/AAAA records have the same value.
Patch Instructions:
   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:
   - SUSE OpenStack Cloud Compute 5:
      zypper in -t patch SUSE-SLE12-CLOUD-5-2015-229=1
   To bring your system up-to-date, use "zypper patch".
Package List:
   - SUSE OpenStack Cloud Compute 5 (x86_64):
      dnsmasq-debuginfo-2.71-4.1
      dnsmasq-debugsource-2.71-4.1
      dnsmasq-utils-2.71-4.1
      dnsmasq-utils-debuginfo-2.71-4.1
References:
   https://www.suse.com/security/cve/CVE-2015-3294.html
   https://bugzilla.suse.com/923144
   https://bugzilla.suse.com/928867
    
    
More information about the sle-updates
mailing list