[Technik] [SECURITY] [DSA 1172-1] New bind9 packages fix denial of service

Noèl Köthe noel at debian.org
Sat Sep 9 13:16:33 CEST 2006


Am Samstag, den 09.09.2006, 08:34 +0200 schrieb Martin Schulze:

> Debian Security Advisory DSA 1172-1                    security at debian.org
> http://www.debian.org/security/                             Martin Schulze
> September 9th, 2006                     http://www.debian.org/security/faq
> 
> Package        : bind9
> Vulnerability  : programming error
> Problem type   : remote
> Debian-specific: no
> CVE IDs        : CVE-2006-4095 CVE-2006-4096
> CERT advisories: VU#697164 VU#915404

bind9 auf pima, pomo, yuma, cusa, h01 (=dns1), h02, h03, cupa (=dns2)
und wasco (=dns3) aktualisiert. Durch die benötigten Neustarts der DNS
Dienste kam es jeweils zu kürzeren einzelnen Ausfällen von DNS.

> For the stable distribution (sarge) these problems have been fixed in
> version 9.2.4-1sarge1.

changelog:
bind9 (1:9.2.4-1sarge1) stable; urgency=low

  * Backport bugfix for 1941 from 9.2.6-P1. Closes: #386237, #386245
    - fixes CVE-2006-4095 and CVE-2006-4096.
    - ncache_adderesult() should set eresult even if no rdataset is passed
      to it. [RT #15642]

 -- LaMont Jones <lamont at debian.org>  Wed,  6 Sep 2006 10:03:20 -0600

-- 
Noèl Köthe <noel at debian.org>
Debian GNU/Linux, www.debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Dies ist ein digital signierter Nachrichtenteil
Url : /archiv/technik/attachments/20060909/454af3c0/attachment.pgp


More information about the Technik mailing list