[Opendnssec-user] remote denial of service in opendnssec 2.1.3 , 2.1.7, 2.1.8rc1

Sébastien Tisserant security at daedelys.org
Sat Jan 23 17:27:18 UTC 2021


Hello All

I found a remote denial of service in opendnssec 2.1.3 debian package. I 
could reproduce it with the last released version(2.1.7) and the release 
candidate version (2.1.8rc1)

Since it's easy to trigger it, how do I report this bug without having 
all Internet knowing it ?
I don't see a security flag when creating a ticket in order to allow 
access only to developers.

On my side, I work on a patch.

-- 
Sébastien Tisserant
security at daedelys.org
GPG Key: 483C9670FF212F75


More information about the Opendnssec-user mailing list