You are here
Home > Preporuke > Ranjivost programskog paketa bind

Ranjivost programskog paketa bind

  • Detalji os-a: FED
  • Važnost: URG
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-12335
2015-07-30 11:45:01
——————————————————————————–

Name : bind
Product : Fedora 22
Version : 9.10.2
Release : 4.P3.fc22
URL : http://www.isc.org/products/BIND/
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.

——————————————————————————–
Update Information:

Update to 9.10.2-P3 to fix CVE-2015-5477
——————————————————————————–
ChangeLog:

* Wed Jul 29 2015 Tomas Hozza <thozza@redhat.com> – 32:9.10.2-4.P3
– Update to 9.10.2-P3 to fix CVE-2015-5477
* Thu Jul 9 2015 Tomas Hozza <thozza@redhat.com> – 32:9.10.2-3.P2
– Update to 9.10.2-P2
* Fri Jun 19 2015 Tomas Hozza <thozza@redhat.com> – 32:9.10.2-2.P1
– Update to 9.10.2-P1
——————————————————————————–
References:

[ 1 ] Bug #1247361 – CVE-2015-5477 bind: TKEY query handling flaw leading to denial of service
https://bugzilla.redhat.com/show_bug.cgi?id=1247361
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update bind’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-12357
2015-07-30 11:45:55
——————————————————————————–

Name : bind
Product : Fedora 21
Version : 9.9.6
Release : 10.P1.fc21
URL : http://www.isc.org/products/BIND/
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.

——————————————————————————–
Update Information:

Include fix for CVE-2015-5477
——————————————————————————–
ChangeLog:

* Wed Jul 29 2015 Tomas Hozza <thozza@redhat.com> – 32:9.9.6-10.P1
– Include fix for CVE-2015-5477
* Thu Jul 9 2015 Tomas Hozza <thozza@redhat.com> – 32:9.9.6-9.P1
– Include fix for CVE-2015-4620
* Mon Feb 23 2015 Tomas Hozza <thozza@redhat.com> – 32:9.9.6-8.P1
– Include fix for CVE-2015-1349
* Mon Feb 2 2015 Tomas Hozza <thozza@redhat.com> – 32:9.9.6-7.P1
– Fix nsupdate server auto-detection (#1184151)
* Fri Dec 12 2014 Tomas Hozza <thozza@redhat.com> – 32:9.9.6-6.P1
– Fix host/nslookup crash when remote server could not be reached (#1172935)
* Tue Dec 9 2014 Tomas Hozza <thozza@redhat.com> – 32:9.9.6-5.P1
– Update to 9.9.6-P1 (CVE-2014-8500)
——————————————————————————–
References:

[ 1 ] Bug #1247361 – CVE-2015-5477 bind: TKEY query handling flaw leading to denial of service
https://bugzilla.redhat.com/show_bug.cgi?id=1247361
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update bind’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-12316
2015-07-29 21:45:42
——————————————————————————–

Name : bind99
Product : Fedora 22
Version : 9.9.7
Release : 6.P2.fc22
URL : http://www.isc.org/products/BIND/
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. This package set contains only export
version of BIND libraries, that are used for building ISC DHCP.

——————————————————————————–
Update Information:

Update to 9.9.7-P2 to fix CVE-2015-5477
——————————————————————————–
ChangeLog:

* Wed Jul 29 2015 Tomas Hozza <thozza@redhat.com> – 9.9.7-6.P2
– Update to 9.9.7-P2 to fix CVE-2015-5477
* Wed Jun 17 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 9.9.7-5
– Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Mon Mar 23 2015 Peter Robinson <pbrobinson@fedoraproject.org> 9.9.7-4
– Don’t ship CHANGES, it’s large and README contains user facing changes
——————————————————————————–
References:

[ 1 ] Bug #1247361 – CVE-2015-5477 bind: TKEY query handling flaw leading to denial of service
https://bugzilla.redhat.com/show_bug.cgi?id=1247361
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update bind99’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
7e

AutorTomislav Protega
Cert idNCERT-REF-2015-08-0003-ADV
CveCVE-2015-5477 CVE-2015-4620 CVE-2015-1349 CVE-2014-8500
ID izvornikaFEDORA-2015-12335 FEDORA-2015-12357 FEDORA-2015-12316
Proizvodbind bind99
Izvorhttp://www.redhat.com
Top
More in Preporuke
Ranjivost programskog paketa ruby-rack

Otkrivena je ranjivost u datoteci lib/rack/utils.rb unutar programskog paketa ruby-rack za Debian. Ranjivost udaljenim napadačima omogućuje izazivanje DoS stanja pomoću...

Close