This update restores the PID file location for bind to the location
before the last security update. For reference, here is the original
advisory text that explains the security problems fixed:
Several cache-poisoning vulnerabilities have been discovered in BIND.
These vulnerabilities are apply only if DNSSEC validation is enabled and
trust anchors have been installed, which is not the default.
The Common Vulnerabilities and Exposures project identifies the
following problems:
CVE-2010-0097
BIND does not properly validate DNSSEC NSEC records, which allows
remote attackers to add the Authenticated Data (AD) flag to a forged
NXDOMAIN response for an existing domain.
CVE-2010-0290
When processing crafted responses containing CNAME or DNAME records,
BIND is subject to a DNS cache poisoning vulnerability, provided that
DNSSEC validation is enabled and trust anchors have been installed.
CVE-2010-0382
When processing certain responses containing o...
Get the latest Linux and open source security news straight to your inbox.