Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2009-1620

Опубликовано: 30 нояб. 2009
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2009-1620: bind security update (MODERATE)

[30:9.3.6-4.P1.1]

  • don't cache unvalidated additional sections (#538744)

Обновленные пакеты

Oracle Linux 5

Oracle Linux ia64

bind

9.3.6-4.P1.el5_4.1

bind-chroot

9.3.6-4.P1.el5_4.1

bind-devel

9.3.6-4.P1.el5_4.1

bind-libbind-devel

9.3.6-4.P1.el5_4.1

bind-libs

9.3.6-4.P1.el5_4.1

bind-sdb

9.3.6-4.P1.el5_4.1

bind-utils

9.3.6-4.P1.el5_4.1

caching-nameserver

9.3.6-4.P1.el5_4.1

Oracle Linux x86_64

bind

9.3.6-4.P1.el5_4.1

bind-chroot

9.3.6-4.P1.el5_4.1

bind-devel

9.3.6-4.P1.el5_4.1

bind-libbind-devel

9.3.6-4.P1.el5_4.1

bind-libs

9.3.6-4.P1.el5_4.1

bind-sdb

9.3.6-4.P1.el5_4.1

bind-utils

9.3.6-4.P1.el5_4.1

caching-nameserver

9.3.6-4.P1.el5_4.1

Oracle Linux i386

bind

9.3.6-4.P1.el5_4.1

bind-chroot

9.3.6-4.P1.el5_4.1

bind-devel

9.3.6-4.P1.el5_4.1

bind-libbind-devel

9.3.6-4.P1.el5_4.1

bind-libs

9.3.6-4.P1.el5_4.1

bind-sdb

9.3.6-4.P1.el5_4.1

bind-utils

9.3.6-4.P1.el5_4.1

caching-nameserver

9.3.6-4.P1.el5_4.1

Связанные CVE

Связанные уязвимости

ubuntu
больше 15 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

redhat
больше 15 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

nvd
больше 15 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

debian
больше 15 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before ...

github
около 3 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.