Uočeni su i ispravljeni sigurnosni propusti u programskom paketu BIND. Zloćudni napadači su ih mogli iskoristiti za otkrivanje osjetljivih informacija i DoS (eng. Denial of Service) napad.
Paket:
BIND 9.x
Operacijski sustavi:
Fedora 15, Fedora 16
Kritičnost:
6.3
Problem:
neodgovarajuće rukovanje datotekama, pogreška u programskoj komponenti
Uočena je greška u komponentama "query.c" i "named" te da programski paket na neodgovarajući način rukuje podacima koji imaju parametar RDATA duljine nule.
Posljedica:
Udaljeni napadač može iskoristiti ranjivosti za otkrivanje osjetljivih informacija i napad uskraćivanjem usluga (DoS).
Rješenje:
Preporuča se primjena službenih programskih rješenja.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-8962
2012-06-07 01:39:08
--------------------------------------------------------------------------------
Name : bind
Product : Fedora 15
Version : 9.8.3
Release : 2.P1.fc15
URL : http://www.isc.org/products/BIND/
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System)
server
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream release which fixes CVE-2012-1667. More
information is available on
http://www.isc.org/software/bind/advisories/cve-2012-1667
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jun 4 2012 Adam Tkac <atkac redhat com> 32:9.8.3-2.P1
- update to 9.8.3-P1 (CVE-2012-1667)
* Thu May 24 2012 Adam Tkac <atkac redhat com> 32:9.8.3-1
- update to 9.8.3
* Tue Apr 24 2012 Adam Tkac <atkac redhat com> 32:9.8.2-1
- update to 9.8.2
- bind-9.5-overflow.patch is no longer needed
* Mon Jan 23 2012 Adam Tkac <atkac redhat com> 32:9.8.2-0.2.rc1
- update to 9.8.2rc1
* Wed Dec 14 2011 Adam Tkac <atkac redhat com> 32:9.8.2-0.1.b1
- update to 9.8.2b1
- patches merged
- bind97-rh700097.patch
* Wed Dec 7 2011 Adam Tkac <atkac redhat com> 32:9.8.1-4.P1
- ship dns/forward.h in -devel subpkg
* Wed Nov 16 2011 Adam Tkac <atkac redhat com> 32:9.8.1-3.P1
- update to 9.8.1-P1 (CVE-2011-4313)
* Mon Sep 26 2011 Adam Tkac <atkac redhat com> 32:9.8.1-2
- remove deps filter, it is no longer needed (#739663)
* Wed Sep 7 2011 Adam Tkac <atkac redhat com> 32:9.8.1-1
- update to 9.8.1
- ship /etc/trusted-key.key (needed by dig)
- use select instead of epoll in export libs (#735103)
* Wed Aug 31 2011 Adam Tkac <atkac redhat com> 32:9.8.1-0.3.rc1
- fix DLZ related compilation issues
- make /etc/named.{root,iscdlv}.key world-readable
- add bind-libs versioned requires to bind pkg
* Wed Aug 31 2011 Adam Tkac <atkac redhat com> 32:9.8.1-0.2.rc1
- fix rare race condition in request.c
- print "the working directory is not writable" as debug message
- re-add configtest target to initscript
- initscript: sybsys name is always named, not named-sdb
- nsupdate returned zero when target zone didn't exist (#700097)
- nsupdate could have failed if server has multiple IPs and the first
was unreachable (#714049)
* Wed Aug 31 2011 Adam Tkac <atkac redhat com> 32:9.8.1-0.1.rc1
- update to 9.8.1rc1
- patches merged
- bind97-rh674334.patch
- bind97-cleanup.patch
- bind98-includes.patch
* Wed Aug 3 2011 Adam Tkac <atkac redhat com> 32:9.8.0-9.P4
- improve patch for #725741
* Tue Jul 26 2011 Adam Tkac <atkac redhat com> 32:9.8.0-8.P4
- named could have crashed during reload when dyndb module is used (#725741)
* Tue Jul 5 2011 Adam Tkac <atkac redhat com> 32:9.8.0-7.P4
- update to 9.8.0-P4
- bind98-libdns-export.patch merged
* Thu Jun 2 2011 Adam Tkac <atkac redhat com> 32:9.8.0-6.P2
- update the dyndb patch
* Fri May 27 2011 Adam Tkac <atkac redhat com> 32:9.8.0-5.P2
- fix compilation of libdns-export.so
* Fri May 27 2011 Adam Tkac <atkac redhat com> 32:9.8.0-4.P2
- update to 9.8.0-P2 (CVE-2011-1910)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #828078 - CVE-2012-1667 bind: handling of zero length rdata can
cause named to terminate unexpectedly
https://bugzilla.redhat.com/show_bug.cgi?id=828078
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update bind' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-8946
2012-06-07 01:38:15
--------------------------------------------------------------------------------
Name : bind
Product : Fedora 16
Version : 9.8.3
Release : 2.P1.fc16
URL : http://www.isc.org/products/BIND/
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System)
server
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream release which fixes CVE-2012-1667. More
information is available on
http://www.isc.org/software/bind/advisories/cve-2012-1667
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jun 4 2012 Adam Tkac <atkac redhat com> 32:9.8.3-2.P1
- update to 9.8.3-P1 (CVE-2012-1667)
* Thu May 24 2012 Adam Tkac <atkac redhat com> 32:9.8.3-1
- update to 9.8.3
* Tue Apr 24 2012 Adam Tkac <atkac redhat com> 32:9.8.2-1
- update to 9.8.2
- bind-9.5-overflow.patch is no longer needed
* Fri Mar 16 2012 Adam Tkac <atkac redhat com> 32:9.8.2-0.4.rc2
- update to 9.8.2rc2
* Fri Mar 16 2012 Adam Tkac <atkac redhat com> 32:9.8.2-0.3.rc1
- load dynamic DB plugins later
* Mon Jan 23 2012 Adam Tkac <atkac redhat com> 32:9.8.2-0.2.rc1
- update to 9.8.2rc1
* Wed Dec 14 2011 Adam Tkac <atkac redhat com> 32:9.8.2-0.1.b1
- update to 9.8.2b1
- patches merged
- bind97-rh700097.patch
* Wed Dec 7 2011 Adam Tkac <atkac redhat com> 32:9.8.1-5.P1
- ship dns/forward.h in -devel subpkg
* Wed Nov 16 2011 Adam Tkac <atkac redhat com> 32:9.8.1-4.P1
- update to 9.8.1-P1 (CVE-2011-4313)
* Mon Sep 26 2011 Adam Tkac <atkac redhat com> 32:9.8.1-3
- remove deps filter, it is no longer needed (#739663)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #828078 - CVE-2012-1667 bind: handling of zero length rdata can
cause named to terminate unexpectedly
https://bugzilla.redhat.com/show_bug.cgi?id=828078
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update bind' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke