TritonDataCenter / pkgsrc

NetBSD/pkgsrc fork for our binary package repositories
https://pkgsrc.smartos.org/
133 stars 50 forks source link

PowerDNS CVE-2022-27227 #331

Closed jfqd closed 1 year ago

jfqd commented 2 years ago

PowerDNS Authoritative Serve from trunk with Version 4.4.1 has a known CVE reported by the security-advisory.

Not affected PowerDNS versions are:

Would it be possible to get a newer version of PowerDNS Authoritative Server and Recursor in trunk?

And there is also a newer version of dnsdist (1.7.1), pkgsrc trunk has currently 1.5.1. Would it be possible to get an update too?

jfqd commented 2 years ago

Would it be possible to get newer versions with the next build-process?

jfqd commented 2 years ago

@jperkin The 4.4 branch of PowerDNS is EOL since this week. Would it be possible to get newer versions (4.5 or 4.6) with the next build-process?

jfqd commented 2 years ago

@jperkin Would it be possible to get a newer version cause of the mentioned CVEs? Otherwise this would be another switch to linux.

jfqd commented 2 years ago

@jperkin Would it be possible to get a newer version cause of the mentioned CVEs from April?

jfqd commented 2 years ago

@jperkin Would it be possible to get the current PowerDNS version 4.6.0 for trunk? Or should we move to LX?

jperkin commented 2 years ago

I've updated both the authoritative server and the recursor to their latest versions, and will kick off a new trunk build once the repository has been updated.

We could always do with more maintainers to help keep packages up-to-date, especially from people who use them in production. Would you be interested in taking these on?

jperkin commented 2 years ago

For reference, here are the commits:

A lot of the changes are simple pkglint cleanups, the actual packaging changes are minimal, with the only difficult part being a compile issue introduced recently in powerdns-recursor that I've fixed and reported upstream.

jfqd commented 2 years ago

@jperkin Thx a lot! Will try the new package on saturday. Send you an email on the maintainer topic.

jfqd commented 2 years ago

@jperkin powerdns-mysql is missing. Update failed for me. Would it be possible to get this package back?

jfqd commented 2 years ago

@jperkin Would it be possible to get the powerdns-mysql package back?

jperkin commented 2 years ago

I've fixed mariadb106 which was blocking this, hopefully it will return in the next build. I'll keep the ticket open until then.

jperkin commented 1 year ago

This is now available again.