Now
MAIN commitmail json YAML
py-dns: updated to 2.6.1
2.6.1
Dnspython 2.6.1 is now available on PyPI. See What窶冱 New for details. This is a
bug fix release for 2.6.0 where the 窶弋uDoor窶� fix erroneously suppressed
legitimate Truncated exceptions. This caused the stub resolver to timeout
instead of failing over to TCP when a legitimate truncated response was
received over UDP. This release addresses the potential DoS issue discussed in
the 窶弋uDoor窶� paper (CVE-2023-29483). The dnspython stub resolver is vulnerable
to a potential DoS if a bad-in-some-way response from the right address and
port forged by an attacker arrives before a legitimate one on the UDP port
dnspython is using for that query.
2.6.1
Dnspython 2.6.1 is now available on PyPI. See What窶冱 New for details. This is a
bug fix release for 2.6.0 where the 窶弋uDoor窶� fix erroneously suppressed
legitimate Truncated exceptions. This caused the stub resolver to timeout
instead of failing over to TCP when a legitimate truncated response was
received over UDP. This release addresses the potential DoS issue discussed in
the 窶弋uDoor窶� paper (CVE-2023-29483). The dnspython stub resolver is vulnerable
to a potential DoS if a bad-in-some-way response from the right address and
port forged by an attacker arrives before a legitimate one on the UDP port
dnspython is using for that query.