Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 11 Jun 2020 19:35:57 +0100
From: Ian Jackson <>
Subject: adns (dns resolver library) multiple vulns

Hi.  I'm the upstream maintainer for adns.  There were outstanding
security problems which I have sat on for far too long, but I have now
finally dealt with them properly.  My apologies.

The fixes have incorporated in adns 1.5.2 and 1.6.0.  See the release
announcement here:

If you prefer to apply specific patches, the relevant commits are
in my git repository:
in this commit range
(which you will find is covered by the signed tag adns-1.5.2).

The most serious problems are remote code execution, within the
adns-using application, exploitable by the local recursive resolver.

Thanks for your attention.


Ian Jackson <>   These opinions are my own.  

Pronouns: they/he.  If I emailed you from or,
that is a private address which bypasses my fierce spamfilter.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.