Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Slackware: 2012-209-01 Critical: Bind Memory Leak Follow-Up

slackware
Calendar Grey July 27, 2012
Dist Slackware Esm H88
Exciting new updates released for Slackware with bind packages rectifying security vulnerabilities and memory optimization issues. Ensure you download the latest enhancements today!
New bind packages are available for Slackware 12.0, 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix security issues

Summary

Here are the details from the Slackware 13.37 ChangeLog: patches/packages/bind-9.7.6_P2-i486-1_slack13.37.txz: Upgraded. Prevents a named assert (crash) when validating caused by using "Bad cache" data before it has been initialized. [RT #30025] ISC_QUEUE handling for recursive clients was updated to address a race condition that could cause a memory leak. This rarely occurred with UDP clients, but could be a significant problem for a server handling a steady rate of TCP queries. [RT #29539 & #30233] Under heavy incoming TCP query loads named could experience a memory leak which could lead to significant reductions in query response or cause the server to be terminated on systems with "out of memory" killers. [RT #29539] A condition has been corrected where improper handling of zero-length RDATA could cause undesirable behavior, including termination of the named process. [RT #29644] (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 12.0: ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/bind-9.7.6_P2-i486-1_slack12.0.tgz
Updated package for Slackware 12.1:
Updated package for Slackware 12.2:
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 12.0 package: 976aa8dc3e374323b0561312c9f1661c bind-9.7.6_P2-i486-1_slack12.0.tgz
Slackware 12.1 package: dbaa53400ffe7a10aa2687653d02d232 bind-9.7.6_P2-i486-1_slack12.1.tgz
Slackware 12.2 package: 1946e8e1e80cbb6c6d1655fc72fb2c18 bind-9.7.6_P2-i486-1_slack12.2.tgz
Slackware 13.0 package: b8f077dc45c9b536edc1c90b26d1cf27 bind-9.7.6_P2-i486-1_slack13.0.txz
Slackware x86_64 13.0 package: 5fd6bb6827e53728d66993385c4afe06 bind-9.7.6_P2-x86_64-1_slack13.0.txz
Slackware 13.1 package: 15acc47f18b3debc0503175c034db1b0 bind-9.7.6_P2-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: e30d42a5f029c663a7a337a5e4352d4c bind-9.7.6_P2-x86_64-1_slack13.1.txz
Slackware 13.37 package: 3c2301eaf1a4aaba2b176bf5e5f47322 bind-9.7.6_P2-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: 8a379f19cd47dc5ec90b9202ac76f5ac bind-9.7.6_P2-x86_64-1_slack13.37.txz
Slackware -current package: 200f8787284d4bbcf752b975936acba3 n/bind-9.9.1_P2-i486-1.txz
Slackware x86_64 -current package: f8d7622c5e1a3c6c8fe65dc91698b6e0 n/bind-9.9.1_P2-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg bind-9.7.6_P2-i486-1_slack13.37.txz Then, restart the name server: # /etc/rc.d/rc.bind restart

Related News

Your message here