Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian 5.0: DSA-2054-2 Critical: Bind9 Cache Poisoning Remote Exploit

debian
Calendar Grey June 15, 2010
Debian Logo
Upgrade the bind9 service to mitigate the risk factors posed by external cache poisoning threats as detailed in DSA 2054-2 for improved protection.
This update restores the PID file location for bind to the location before the last security update

Summary

This update restores the PID file location for bind to the location
before the last security update. For reference, here is the original
advisory text that explains the security problems fixed:

Several cache-poisoning vulnerabilities have been discovered in BIND.
These vulnerabilities are apply only if DNSSEC validation is enabled and
trust anchors have been installed, which is not the default.

The Common Vulnerabilities and Exposures project identifies the
following problems:

CVE-2010-0097
BIND does not properly validate DNSSEC NSEC records, which allows
remote attackers to add the Authenticated Data (AD) flag to a forged
NXDOMAIN response for an existing domain.

CVE-2010-0290
When processing crafted responses containing CNAME or DNAME records,
BIND is subject to a DNS cache poisoning vulnerability, provided that
DNSSEC validation is enabled and trust anchors have been installed.

CVE-2010-0382
When processing certain responses containing o...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: bind9

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here