Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora: 2009-5191 Moderate: NSD DNS Server Overflow Exploit

fedora
Calendar Grey May 19, 2009
Dist Fedora Esm H88
Fedora 10 nsd patch addresses one-byte buffer overflow vulnerability affecting DNS systems with low exploit likelihood. Update immediately!
Security release

Summary

NSD is a complete implementation of an authoritative DNS name server.

For further information about what NSD is and what NSD is not please

consult the REQUIREMENTS document which is a part of this distribution

(thanks to Olaf).

Update Information:

Security release. A one-byte overflow bug allows a carefully crafted exploit to bring down your DNS server. It is highly unlikely that this one byte overflow can lead to other (system) exploits.

Change Log

* Mon May 18 2009 Paul Wouters - 3.2.2-2 - Bump version * Mon May 18 2009 Paul Wouters - 3.2.2-1 - Upgraded to 3.2.2 security release - Removed obsoleted options --enable-plugins --enable-mmap * Fri Apr 10 2009 Paul Wouters - 3.2.1-1 - updated to 3.2.1 - fixed /dev/nul which cause a file \%1 to be written by cron - merged in Ville Mattila's patches for nsd initscript and sysconfig

References

Fedora Update Notification FEDORA-2009-5191 2009-05-19 23:55:54
Name : nsd Product : Fedora 10 Version : 3.2.2 Release : 2.fc10 URL : https://www.nlnetlabs.nl/projects/nsd/about/ Summary : Fast and lean authoritative DNS Name Server Description : NSD is a complete implementation of an authoritative DNS name server. For further information about what NSD is and what NSD is not please consult the REQUIREMENTS document which is a part of this distribution (thanks to Olaf).

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update nsd' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: nsd
Product: Fedora 10
Version: 3.2.2
Release: 2.fc10
Summary: Fast and lean authoritative DNS Name Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here