Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:1205-1

Опубликовано: 27 янв. 2014
Источник: suse-cvrf

Описание

Security update for bind

This update fixes a DoS vulnerability in bind when handling malformed NSEC3-signed zones. CVE-2014-0591 has been assigned to this issue.

Security Issue references:

* CVE-2014-0591 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0591>

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
bind-libs-9.9.4P2-0.6.1
bind-libs-32bit-9.9.4P2-0.6.1
bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Server 11 SP3
bind-9.9.4P2-0.6.1
bind-chrootenv-9.9.4P2-0.6.1
bind-doc-9.9.4P2-0.6.1
bind-libs-9.9.4P2-0.6.1
bind-libs-32bit-9.9.4P2-0.6.1
bind-libs-x86-9.9.4P2-0.6.1
bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
bind-9.9.4P2-0.6.1
bind-chrootenv-9.9.4P2-0.6.1
bind-doc-9.9.4P2-0.6.1
bind-libs-9.9.4P2-0.6.1
bind-libs-32bit-9.9.4P2-0.6.1
bind-libs-x86-9.9.4P2-0.6.1
bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3
bind-9.9.4P2-0.6.1
bind-chrootenv-9.9.4P2-0.6.1
bind-doc-9.9.4P2-0.6.1
bind-libs-9.9.4P2-0.6.1
bind-libs-32bit-9.9.4P2-0.6.1
bind-libs-x86-9.9.4P2-0.6.1
bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Software Development Kit 11 SP3
bind-devel-9.9.4P2-0.6.1
bind-devel-32bit-9.9.4P2-0.6.1

Описание

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-32bit-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:bind-9.9.4P2-0.6.1

Ссылки

Описание

The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-32bit-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:bind-9.9.4P2-0.6.1

Ссылки

Описание

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-32bit-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:bind-9.9.4P2-0.6.1

Ссылки

Описание

named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-32bit-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:bind-9.9.4P2-0.6.1

Ссылки

Описание

name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zone data and then making a query for a name in that zone.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-32bit-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-libs-9.9.4P2-0.6.1
SUSE Linux Enterprise Desktop 11 SP3:bind-utils-9.9.4P2-0.6.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:bind-9.9.4P2-0.6.1

Ссылки
Уязвимость SUSE-SU-2015:1205-1