Описание
Security update for bind
This update fixes a DoS vulnerability in bind when handling malformed NSEC3-signed zones. CVE-2014-0591 has been assigned to this issue.
Security Issue references:
Список пакетов
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP3
SUSE Linux Enterprise Software Development Kit 11 SP3
Ссылки
- Link for SUSE-SU-2015:1205-1
- E-Mail link for SUSE-SU-2015:1205-1
- SUSE Security Ratings
- SUSE Bug 743758
- SUSE Bug 815230
- SUSE Bug 819475
- SUSE Bug 831899
- SUSE Bug 858639
- SUSE Bug 882511
- SUSE Bug 908994
- SUSE Bug 918330
- SUSE Bug 936476
- SUSE CVE CVE-2013-4854 page
- SUSE CVE CVE-2014-0591 page
- SUSE CVE CVE-2014-8500 page
- SUSE CVE CVE-2015-1349 page
- SUSE CVE CVE-2015-4620 page
Описание
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.
Затронутые продукты
Ссылки
- CVE-2013-4854
- SUSE Bug 831899
Описание
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
Затронутые продукты
Ссылки
- CVE-2014-0591
- SUSE Bug 858639
Описание
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
Затронутые продукты
Ссылки
- CVE-2014-8500
- SUSE Bug 908994
- SUSE Bug 986950
Описание
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
Затронутые продукты
Ссылки
- CVE-2015-1349
- SUSE Bug 918330
Описание
name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zone data and then making a query for a name in that zone.
Затронутые продукты
Ссылки
- CVE-2015-4620
- SUSE Bug 936476