U radu programskog paketa BIND, za operacijske sustave Fedora 14 i 15, uočen je sigurnosni propust koji udaljenom napadaču omogućuje izvođenje napada uskraćivanjem usluge (DoS).
Paket: | BIND 9.7.x, BIND 9.x |
Operacijski sustavi: | Fedora 14, Fedora 15 |
Kritičnost: | 3.7 |
Problem: | pogreška u programskoj komponenti |
Iskorištavanje: | udaljeno |
Posljedica: | uskraćivanje usluga (DoS) |
Rješenje: | programska zakrpa proizvođača |
CVE: | CVE-2011-4313 |
Izvorni ID preporuke: | FEDORA-2011-16002 |
Izvor: | Fedora |
Problem: | |
Propust je posljedica pogreške u obradi rekurzivnih upita. |
|
Posljedica: | |
Napadač ga može iskoristiti za izvođenje DoS (eng. Denial of Service) napada. |
|
Rješenje: | |
Svim se korisnicima savjetuje instalacija nadogradnje. |
Izvorni tekst preporuke
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-16002
2011-11-17 22:45:45
--------------------------------------------------------------------------------
Name : bind
Product : Fedora 14
Version : 9.7.4
Release : 2.P1.fc14
URL : http://www.isc.org/products/BIND/
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System)
server
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.
--------------------------------------------------------------------------------
Update Information:
Update to the 9.7.4-P1 security release which fixes CVE-2011-4313.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 16 2011 Adam Tkac <atkac redhat com> 32:9.7.4-2.P1
- update to 9.7.4-P1 (CVE-2011-4313)
* Tue Aug 2 2011 Adam Tkac <atkac redhat com> 32:9.7.4-1
- update to 9.7.4
- bind97-CVE-2011-1910.patch merged
- bind97-CVE-2011-2464.patch merged
* Wed Jul 6 2011 Adam Tkac <atkac redhat com> 32:9.7.4-0.3.b1
- fix CVE-2011-2464
* Fri May 27 2011 Adam Tkac <atkac redhat com> 32:9.7.4-0.2.b1
- fix CVE-2011-1910
* Tue May 17 2011 Adam Tkac <atkac redhat com> 32:9.7.4-0.1.b1
- update to 9.7.4b1 (#683648)
- bind97-rh674334.patch merged
- bind97-rh665971.patch merged
- bind97-cleanup.patch merged
* Fri Feb 18 2011 Adam Tkac <atkac redhat com> 32:9.7.3-1
- update to 9.7.3
- bind97-krb5-self.patch merged
- fix dig +trace on dualstack systems (#674334)
- fix linkage order when building on system with older BIND (#665971)
- reduce number of gcc warnings
* Mon Dec 20 2010 Adam Tkac <atkac redhat com> 32:9.7.2-5.P3
- fix "krb5-self" update-policy rule processing
* Thu Dec 2 2010 Adam Tkac <atkac redhat com> 32:9.7.2-4.P3
- update to 9.7.2-P3
* Mon Nov 8 2010 Adam Tkac <atkac redhat com> 32:9.7.2-3.P2
- don't emit various informational messages by default (#645544)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #754509 - bind: Remote denial of service against recursive servers
via logging negative cache entry [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=754509
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update bind' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-16036
2011-11-17 22:47:35
--------------------------------------------------------------------------------
Name : bind
Product : Fedora 15
Version : 9.8.1
Release : 3.P1.fc15
URL : http://www.isc.org/products/BIND/
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System)
server
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.
--------------------------------------------------------------------------------
Update Information:
Update to the 9.8.1-P1 security release which fixes CVE-2011-4313.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Nov 16 2011 Adam Tkac <atkac redhat com> 32:9.8.1-3.P1
- update to 9.8.1-P1 (CVE-2011-4313)
* Mon Sep 26 2011 Adam Tkac <atkac redhat com> 32:9.8.1-2
- remove deps filter, it is no longer needed (#739663)
* Wed Sep 7 2011 Adam Tkac <atkac redhat com> 32:9.8.1-1
- update to 9.8.1
- ship /etc/trusted-key.key (needed by dig)
- use select instead of epoll in export libs (#735103)
* Wed Aug 31 2011 Adam Tkac <atkac redhat com> 32:9.8.1-0.3.rc1
- fix DLZ related compilation issues
- make /etc/named.{root,iscdlv}.key world-readable
- add bind-libs versioned requires to bind pkg
* Wed Aug 31 2011 Adam Tkac <atkac redhat com> 32:9.8.1-0.2.rc1
- fix rare race condition in request.c
- print "the working directory is not writable" as debug message
- re-add configtest target to initscript
- initscript: sybsys name is always named, not named-sdb
- nsupdate returned zero when target zone didn't exist (#700097)
- nsupdate could have failed if server has multiple IPs and the first
was unreachable (#714049)
* Wed Aug 31 2011 Adam Tkac <atkac redhat com> 32:9.8.1-0.1.rc1
- update to 9.8.1rc1
- patches merged
- bind97-rh674334.patch
- bind97-cleanup.patch
- bind98-includes.patch
* Wed Aug 3 2011 Adam Tkac <atkac redhat com> 32:9.8.0-9.P4
- improve patch for #725741
* Tue Jul 26 2011 Adam Tkac <atkac redhat com> 32:9.8.0-8.P4
- named could have crashed during reload when dyndb module is used (#725741)
* Tue Jul 5 2011 Adam Tkac <atkac redhat com> 32:9.8.0-7.P4
- update to 9.8.0-P4
- bind98-libdns-export.patch merged
* Thu Jun 2 2011 Adam Tkac <atkac redhat com> 32:9.8.0-6.P2
- update the dyndb patch
* Fri May 27 2011 Adam Tkac <atkac redhat com> 32:9.8.0-5.P2
- fix compilation of libdns-export.so
* Fri May 27 2011 Adam Tkac <atkac redhat com> 32:9.8.0-4.P2
- update to 9.8.0-P2 (CVE-2011-1910)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #754509 - bind: Remote denial of service against recursive servers
via logging negative cache entry [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=754509
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update bind' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke