Описание
ELSA-2008-0300: bind security, bug fix, and enhancement update (MODERATE)
[30:9.3.4-6.P1]
- final 5.2 version
- minor changes in initscript
- improved patches for #250744 and #250901
[30:9.3.4-5.P1]
- improved patch to handle D-BUS races (#240876)
- updated named.root zone to affect root IPv6 migration
[30:9.3.4-4.P1]
- improved fix for #253537, posttrans script is now used
- do not call restorecon on chroot/proc
[30:9.3.4-3.P1]
- CVE-2008-0122 (small buffer overflow in inet_network)
[30:9.3.4-2.P1]
- ship /usr/include/dst/gssapi.h file
[30:9.3.4-1.P1]
- CVE-2007-6283 (#419421)
[30:9.3.4-0.9.2.P1]
- added GSS-TSIG support to nsupdate (#251528)
[30:9.3.4-0.9.1.P1]
- updated L.ROOT-SERVERS.NET address in lib/dns/rootns.c file
[30:9.3.4-0.9.P1]
- fixed building of SDB stuff (#240788)
- fixed race condition during DBUS initialization (#240876)
- initscript LSD standardization (#242734) [command (#247148)]
- fixed wrong perms of named's ldap schema (#250118)
- supressed errors from chroot's specfile scripts (#252334)
- fixed /dev/random SELinux labelling
- added configtest to usage report from named initscript (#250744)
- fixed rndc stop return value handler (#250901)
- fixed named.log sync in bind-chroot-admin (#247486)
- rebased to latest 9.3 maintenance release (9.3.4-P1, #353741)
- updated named.root file (new L.ROOT-SERVERS.NET, #363531)
- added GSS-TSIG support to named (#251528)
- dropped patches (upstream)
- bind-9.3.4.P1-query-id.patch
- bind-9.3.3rc2-dbus-0.6.patch
- bind-9.3.4-validator.patch
- bind-9.3.4-nqueries.patch
- updated patches
- bind-9.3.2-tmpfile.patch
- dropped patches (upstream)
Обновленные пакеты
Oracle Linux 5
Oracle Linux x86_64
bind
9.3.4-6.P1.el5
bind-chroot
9.3.4-6.P1.el5
bind-devel
9.3.4-6.P1.el5
bind-libbind-devel
9.3.4-6.P1.el5
bind-libs
9.3.4-6.P1.el5
bind-sdb
9.3.4-6.P1.el5
bind-utils
9.3.4-6.P1.el5
caching-nameserver
9.3.4-6.P1.el5
Oracle Linux i386
bind
9.3.4-6.P1.el5
bind-chroot
9.3.4-6.P1.el5
bind-devel
9.3.4-6.P1.el5
bind-libbind-devel
9.3.4-6.P1.el5
bind-libs
9.3.4-6.P1.el5
bind-sdb
9.3.4-6.P1.el5
bind-utils
9.3.4-6.P1.el5
caching-nameserver
9.3.4-6.P1.el5
Связанные CVE
Связанные уязвимости
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Off-by-one error in the inet_network function in libbind in ISC BIND 9 ...
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.