Date:         Tue, 24 Jul 2007 17:20:02 -0500
Reply-To:     Connie Sieh 
Sender:       Security Errata for Scientific Linux
              
From:         Connie Sieh 
Subject:      FASTBUGS rpms for SL 4.x x86_64
Comments: To: scientific 
Comments: cc: scientific-linux-users@fnal.gov

The following fastbug rpms are now available at

/
/

apr-0.9.4-24.9.i386.rpm
apr-0.9.4-24.9.x86_64.rpm
apr-devel-0.9.4-24.9.x86_64.rpm
busybox-1.00.rc1-8.el4.x86_64.rpm
busybox-anaconda-1.00.rc1-8.el4.x86_64.rpm
crypto-utils-2.1-4.2.x86_64.rpm
db4-4.2.52-7.3.el4.i386.rpm
db4-4.2.52-7.3.el4.x86_64.rpm
db4-devel-4.2.52-7.3.el4.x86_64.rpm
db4-java-4.2.52-7.3.el4.x86_64.rpm
db4-tcl-4.2.52-7.3.el4.x86_64.rpm
db4-utils-4.2.52-7.3.el4.x86_64.rpm
device-mapper-1.02.17-3.0.1.el4.i386.rpm
device-mapper-1.02.17-3.0.1.el4.x86_64.rpm
dia-0.94-5.7.2.x86_64.rpm
gzip-1.3.3-17.rhel4.x86_64.rpm
libtool-1.5.6-4.EL4.2.x86_64.rpm
libtool-libs-1.5.6-4.EL4.2.i386.rpm
libtool-libs-1.5.6-4.EL4.2.x86_64.rpm
perl-Archive-Tar-1.30-1.el4.noarch.rpm
perl-Compress-Zlib-1.42-1.el4.x86_64.rpm
perl-IO-String-1.08-1.1.el4.noarch.rpm
perl-IO-Zlib-1.04-4.2.el4.noarch.rpm
perl-TimeDate-1.16-5.el4.noarch.rpm
pidgin-1.5.1-1.el4.x86_64.rpm
planner-0.12.1-2.2.x86_64.rpm
rp-pppoe-3.5-22.2.RHEL4.1.x86_64.rpm
spamassassin-3.1.9-1.el4.1.x86_64.rpm
sysstat-5.0.5-15.0.1.el4.x86_64.rpm
up2date-4.5.5-7.el4.x86_64.rpm
up2date-gnome-4.5.5-7.el4.x86_64.rpm

-Connie Sieh
Date:         Mon, 30 Jul 2007 16:26:44 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for bind on SL5.x, SL4.x, SL3,x i386/x86_64
Comments: To: scientific-linux-errata@fnal.gov

Synopsis:	Moderate: bind security update
Issue date:	2007-07-24
CVE Names:	CVE-2007-2926

A flaw was found in the way BIND generates outbound DNS query ids. If an
attacker is able to acquire a finite set of query IDs, it becomes possible
to accurately predict future query IDs. Future query ID prediction may
allow an attacker to conduct a DNS cache poisoning attack, which can result
in the DNS server returning incorrect client query data. (CVE-2007-2926)

SL 3.0.x

   SRPMS:
	bind-9.2.4-21.el3.src.rpm
   i386:
	bind-9.2.4-21.el3.i386.rpm
	bind-chroot-9.2.4-21.el3.i386.rpm
	bind-devel-9.2.4-21.el3.i386.rpm
	bind-libs-9.2.4-21.el3.i386.rpm
	bind-utils-9.2.4-21.el3.i386.rpm
   x86_64:
	bind-9.2.4-21.el3.x86_64.rpm
	bind-chroot-9.2.4-21.el3.x86_64.rpm
	bind-devel-9.2.4-21.el3.x86_64.rpm
	bind-libs-9.2.4-21.el3.x86_64.rpm
	bind-utils-9.2.4-21.el3.x86_64.rpm

SL 4.x

   SRPMS:
	bind-9.2.4-27.0.1.el4.src.rpm
   i386:
	bind-9.2.4-27.0.1.el4.i386.rpm
	bind-chroot-9.2.4-27.0.1.el4.i386.rpm
	bind-devel-9.2.4-27.0.1.el4.i386.rpm
	bind-libs-9.2.4-27.0.1.el4.i386.rpm
	bind-utils-9.2.4-27.0.1.el4.i386.rpm
   x86_64:
	bind-9.2.4-27.0.1.el4.x86_64.rpm
	bind-chroot-9.2.4-27.0.1.el4.x86_64.rpm
	bind-devel-9.2.4-27.0.1.el4.x86_64.rpm
	bind-libs-9.2.4-27.0.1.el4.i386.rpm
	bind-libs-9.2.4-27.0.1.el4.x86_64.rpm
	bind-utils-9.2.4-27.0.1.el4.x86_64.rpm

SL 5.x

   SRPMS:
	bind-9.3.3-9.0.1.el5.src.rpm
   i386:
	bind-9.3.3-9.0.1.el5.i386.rpm
	bind-chroot-9.3.3-9.0.1.el5.i386.rpm
	bind-devel-9.3.3-9.0.1.el5.i386.rpm
	bind-libbind-devel-9.3.3-9.0.1.el5.i386.rpm
	bind-libs-9.3.3-9.0.1.el5.i386.rpm
	bind-sdb-9.3.3-9.0.1.el5.i386.rpm
	bind-utils-9.3.3-9.0.1.el5.i386.rpm
	caching-nameserver-9.3.3-9.0.1.el5.i386.rpm
   x86_64:
	bind-9.3.3-9.0.1.el5.x86_64.rpm
	bind-chroot-9.3.3-9.0.1.el5.x86_64.rpm
	bind-devel-9.3.3-9.0.1.el5.i386.rpm
	bind-devel-9.3.3-9.0.1.el5.x86_64.rpm
	bind-libbind-devel-9.3.3-9.0.1.el5.i386.rpm
	bind-libbind-devel-9.3.3-9.0.1.el5.x86_64.rpm
	bind-libs-9.3.3-9.0.1.el5.i386.rpm
	bind-libs-9.3.3-9.0.1.el5.x86_64.rpm
	bind-sdb-9.3.3-9.0.1.el5.x86_64.rpm
	bind-utils-9.3.3-9.0.1.el5.x86_64.rpm
	caching-nameserver-9.3.3-9.0.1.el5.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2007-2926 bind SL5.x, SL4.x, SL3,x i386/x86_64

Moderate: bind security update

Summary

Date:         Tue, 24 Jul 2007 17:20:02 -0500Reply-To:     Connie Sieh Sender:       Security Errata for Scientific Linux              From:         Connie Sieh Subject:      FASTBUGS rpms for SL 4.x x86_64Comments: To: scientific Comments: cc: scientific-linux-users@fnal.govThe following fastbug rpms are now available at//apr-0.9.4-24.9.i386.rpmapr-0.9.4-24.9.x86_64.rpmapr-devel-0.9.4-24.9.x86_64.rpmbusybox-1.00.rc1-8.el4.x86_64.rpmbusybox-anaconda-1.00.rc1-8.el4.x86_64.rpmcrypto-utils-2.1-4.2.x86_64.rpmdb4-4.2.52-7.3.el4.i386.rpmdb4-4.2.52-7.3.el4.x86_64.rpmdb4-devel-4.2.52-7.3.el4.x86_64.rpmdb4-java-4.2.52-7.3.el4.x86_64.rpmdb4-tcl-4.2.52-7.3.el4.x86_64.rpmdb4-utils-4.2.52-7.3.el4.x86_64.rpmdevice-mapper-1.02.17-3.0.1.el4.i386.rpmdevice-mapper-1.02.17-3.0.1.el4.x86_64.rpmdia-0.94-5.7.2.x86_64.rpmgzip-1.3.3-17.rhel4.x86_64.rpmlibtool-1.5.6-4.EL4.2.x86_64.rpmlibtool-libs-1.5.6-4.EL4.2.i386.rpmlibtool-libs-1.5.6-4.EL4.2.x86_64.rpmperl-Archive-Tar-1.30-1.el4.noarch.rpmperl-Compress-Zlib-1.42-1.el4.x86_64.rpmperl-IO-String-1.08-1.1.el4.noarch.rpmperl-IO-Zlib-1.04-4.2.el4.noarch.rpmperl-TimeDate-1.16-5.el4.noarch.rpmpidgin-1.5.1-1.el4.x86_64.rpmplanner-0.12.1-2.2.x86_64.rpmrp-pppoe-3.5-22.2.RHEL4.1.x86_64.rpmspamassassin-3.1.9-1.el4.1.x86_64.rpmsysstat-5.0.5-15.0.1.el4.x86_64.rpmup2date-4.5.5-7.el4.x86_64.rpmup2date-gnome-4.5.5-7.el4.x86_64.rpm-Connie SiehDate:         Mon, 30 Jul 2007 16:26:44 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for bind on SL5.x, SL4.x, SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis:	Moderate: bind security updateIssue date:	2007-07-24CVE Names:	CVE-2007-2926A flaw was found in the way BIND generates outbound DNS query ids. If anattacker is able to acquire a finite set of query IDs, it becomes possibleto accurately predict future query IDs. Future query ID prediction mayallow an attacker to conduct a DNS cache poisoning attack, which can resultin the DNS server returning incorrect client query data. (CVE-2007-2926)SL 3.0.x   SRPMS:	bind-9.2.4-21.el3.src.rpm   i386:	bind-9.2.4-21.el3.i386.rpm	bind-chroot-9.2.4-21.el3.i386.rpm	bind-devel-9.2.4-21.el3.i386.rpm	bind-libs-9.2.4-21.el3.i386.rpm	bind-utils-9.2.4-21.el3.i386.rpm   x86_64:	bind-9.2.4-21.el3.x86_64.rpm	bind-chroot-9.2.4-21.el3.x86_64.rpm	bind-devel-9.2.4-21.el3.x86_64.rpm	bind-libs-9.2.4-21.el3.x86_64.rpm	bind-utils-9.2.4-21.el3.x86_64.rpmSL 4.x   SRPMS:	bind-9.2.4-27.0.1.el4.src.rpm   i386:	bind-9.2.4-27.0.1.el4.i386.rpm	bind-chroot-9.2.4-27.0.1.el4.i386.rpm	bind-devel-9.2.4-27.0.1.el4.i386.rpm	bind-libs-9.2.4-27.0.1.el4.i386.rpm	bind-utils-9.2.4-27.0.1.el4.i386.rpm   x86_64:	bind-9.2.4-27.0.1.el4.x86_64.rpm	bind-chroot-9.2.4-27.0.1.el4.x86_64.rpm	bind-devel-9.2.4-27.0.1.el4.x86_64.rpm	bind-libs-9.2.4-27.0.1.el4.i386.rpm	bind-libs-9.2.4-27.0.1.el4.x86_64.rpm	bind-utils-9.2.4-27.0.1.el4.x86_64.rpmSL 5.x   SRPMS:	bind-9.3.3-9.0.1.el5.src.rpm   i386:	bind-9.3.3-9.0.1.el5.i386.rpm	bind-chroot-9.3.3-9.0.1.el5.i386.rpm	bind-devel-9.3.3-9.0.1.el5.i386.rpm	bind-libbind-devel-9.3.3-9.0.1.el5.i386.rpm	bind-libs-9.3.3-9.0.1.el5.i386.rpm	bind-sdb-9.3.3-9.0.1.el5.i386.rpm	bind-utils-9.3.3-9.0.1.el5.i386.rpm	caching-nameserver-9.3.3-9.0.1.el5.i386.rpm   x86_64:	bind-9.3.3-9.0.1.el5.x86_64.rpm	bind-chroot-9.3.3-9.0.1.el5.x86_64.rpm	bind-devel-9.3.3-9.0.1.el5.i386.rpm	bind-devel-9.3.3-9.0.1.el5.x86_64.rpm	bind-libbind-devel-9.3.3-9.0.1.el5.i386.rpm	bind-libbind-devel-9.3.3-9.0.1.el5.x86_64.rpm	bind-libs-9.3.3-9.0.1.el5.i386.rpm	bind-libs-9.3.3-9.0.1.el5.x86_64.rpm	bind-sdb-9.3.3-9.0.1.el5.x86_64.rpm	bind-utils-9.3.3-9.0.1.el5.x86_64.rpm	caching-nameserver-9.3.3-9.0.1.el5.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News