Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Fedora 35: 2021-33622 Urgent OpenSSL Vulnerability Remedy

fedora
Calendar Grey November 27, 2009
Dist Fedora Esm H88
Patch for Fedora 11: address significant cache poisoning vulnerability. Make sure DNSSEC validation is mandatory for enhanced protection.
Update to 9.6.1-P2 release which contains following fix: * Additional section of response could be cached without successful DNSSEC validation even if DNSSEC validation is enabled

Summary

BIND (Berkeley Internet Name Domain) is an implementation of the DNS

(Domain Name System) protocols. BIND includes a DNS server (named),

which resolves host names to IP addresses; a resolver library

(routines for applications to use when interfacing with DNS); and

tools for verifying that the DNS server is operating properly.

Update Information:

Update to 9.6.1-P2 release which contains following fix: * Additional section of response could be cached without successful DNSSEC validation even if DNSSEC validation is enabled

Change Log

* Wed Nov 25 2009 Adam Tkac 32:9.6.1-7.P2 - update to 9.6.1-P2 (CVE-2009-4022) * Mon Sep 21 2009 Adam Tkac 32:9.6.1-6.P1 - determine file size via `stat` instead of `ls` (#523682) * Tue Sep 15 2009 Adam Tkac 32:9.6.1-5.P1 - fix libs postun section again (#514728) - improve chroot related documentation (#507795) - add NetworkManager dispatcher script to reload named when network interface is activated/deactivated (#490275) - don't set/unset named_write_master_zones SELinux boolean every time in initscript, modify it only when it's actually needed * Thu Sep 3 2009 Martin Nagy 32:9.6.1-4.P1.1 - update the patch for dynamic loading of database backends * Wed Jul 29 2009 Adam Tkac 32:9.6.1-4.P1 - 9.6.1-P1 release (CVE-2009-0696) - fix postun trigger (#513016, hopefully) * Mon Jul 13 2009 Adam Tkac 32:9.6.1-3 - fix broken symlinks in bind-libs (#509635) - fix typos in /etc/sysconfig/named (#509650) - add DEBUG option to /etc/sysconfig/named (#510283) * Wed Jun 24 2009 Adam Tkac 32:9.6.1-2 - improved "chroot automount" patches (#504596) - host should fail if specified server doesn't respond (#507469) * Thu Jun 18 2009 Adam Tkac 32:9.6.1-1 - 9.6.1 release - simplify chroot maintenance. Important files and directories are mounted into chroot (see /etc/sysconfig/named for more info, #504596) - fix doc/named.conf.default perms * Wed May 27 2009 Adam Tkac 32:9.6.1-0.4.rc1 - 9.6.1rc1 release

References


[ 1 ] Bug #538744 - CVE-2009-4022 bind: cache poisoning using not validated DNSSEC responses https://bugzilla.redhat.com/show_bug.cgi?id=538744

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update bind' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: bind
Product: Fedora 11
Version: 9.6.1
Release: 7.P2.fc11
URL: Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here