Otkriven je i otklonjen sigurnosni nedostatak u radu programskog paketa bind. Zlonamjerni korisnici su mogli iskoristiti navedeni propust za čitanje osjetljivih podataka ili DoS (eng. Denial of Service) napad.
Paket:
BIND 9.x
Operacijski sustavi:
SUSE Linux Enterprise Desktop 10, SUSE Linux Enterprise Desktop 11, SUSE Linux Enterprise Server (SLES) 9, SUSE Linux Enterprise Server (SLES) 10, SUSE Linux Enterprise Server (SLES) 11
SUSE Security Update: Security update for bind
______________________________________________________________________________
Announcement ID: SUSE-SU-2012:0741-6
Rating: important
References: #765315
Cross-References: CVE-2012-1667
Affected Products:
SUSE CORE 9
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
The following issue has been fixed:
* Records with zero length rdata field could have
crashed named or disclose portions of memory to clients
(CVE-2012-1667).
Security Issue reference:
* CVE-2012-1667
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1667
>
Package List:
- SUSE CORE 9 (i586 s390 s390x x86_64):
bind-9.3.4-4.16
bind-devel-9.3.4-4.16
bind-utils-9.3.4-4.16
- SUSE CORE 9 (x86_64):
bind-utils-32bit-9-201207061338
- SUSE CORE 9 (s390x):
bind-utils-32bit-9-201207061342
References:
http://support.novell.com/security/cve/CVE-2012-1667.html
https://bugzilla.novell.com/765315
http://download.novell.com/patch/finder/?keywords=2f883f124c996f4e73d94255fee4adfc
--
To unsubscribe, e-mail: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
For additional commands, e-mail: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke