FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

consul -- vulnerability in embedded DNS library

Affected packages
consul < 1.0.5

Details

VuXML ID ad2eeab6-ca68-4f06-9325-1937b237df60
Discovery 2018-01-17
Entry 2018-02-16

Consul developers report:

A flaw was found in the embedded DNS library used in consul which may allow a denial of service attack. Consul was updated to include the fixed version.

References

CVE Name CVE-2017-15133
URL https://github.com/hashicorp/consul/blob/master/CHANGELOG.md#105-february-7-2018
URL https://github.com/hashicorp/consul/issues/3859
URL https://github.com/miekg/dns/issues/627
URL https://github.com/miekg/dns/pull/631