Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA-2309-1 Urgent OpenSSL Denial Of Service Update

debian
Calendar Grey March 30, 2011
Debian Logo
BIND enhancement addresses synchronization conflicts, lock contention, and DNSSEC vulnerabilities. Critical update for both stable and testing branches of Debian.
It was discovered that BIND, a DNS server, contains a race condition when processing zones updates in an authoritative server, either through dynamic DNS updates or incremental zon...

Summary

It was discovered that BIND, a DNS server, contains a race condition
when processing zones updates in an authoritative server, either
through dynamic DNS updates or incremental zone transfer (IXFR). Such
an update while processing a query could result in deadlock and denial
of service. (CVE-2011-0414)

In addition, this security update addresses a defect related to the
processing of new DNSSEC DS records by the caching resolver, which may
lead to name resolution failures in the delegated zone. If DNSSEC
validation is enabled, this issue can make domains ending in .COM
unavailable when the DS record for .COM is added to the DNS root zone
on March 31st, 2011. An unpatched server which is affected by this
issue can be restarted, thus re-enabling resolution of .COM domains.
This workaround applies to the version in oldstable, too.

Configurations not using DNSSEC validations are not affected by this
second issue.

For the oldstable distribution (lenny), the DS record issue will be
fixed soon. (CVE-20...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: bind9
CVE ID: CVE-2011-0414

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here