Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Slackware 14.0: 2013-218-01 Critical: Bind Denial Of Service

slackware
Calendar Grey August 6, 2013
Scroller Slackware
Recent updates for BIND in Slackware address a significant DoS vulnerability impacting several versions. Ensure you upgrade immediately!
New bind packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, 14.0, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.0 ChangeLog: patches/packages/bind-9.9.3_P2-i486-1_slack14.0.txz: Upgraded. This update fixes a security issue where a specially crafted query can cause BIND to terminate abnormally, resulting in a denial of service. For more information, see: https://kb.isc.org/docs/aa-01015 https://www.cve.org/CVERecord?id=CVE-2013-4854 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 12.1: ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/bind-9.8.5_P2-i486-1_slack12.1.tgz
Updated package for Slackware 12.2: ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/bind-9.8.5_P2-i486-1_slack12.2.tgz
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 12.1 package: b71ecb3585584e533a3120fb5b455108 bind-9.8.5_P2-i486-1_slack12.1.tgz
Slackware 12.2 package: 636519bd25abc6d98fe888b69b0cb7ab bind-9.8.5_P2-i486-1_slack12.2.tgz
Slackware 13.0 package: 6aca45be4b57ad94424055ec2c0be44f bind-9.8.5_P2-i486-1_slack13.0.txz
Slackware x86_64 13.0 package: d4be81a262b7d43d04c370f54749c27e bind-9.8.5_P2-x86_64-1_slack13.0.txz
Slackware 13.1 package: b1398b8594850bfcfefc80a9771750c9 bind-9.8.5_P2-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: 5a4c6cd8631b928ec499583bed4950cb bind-9.8.5_P2-x86_64-1_slack13.1.txz
Slackware 13.37 package: 695ccd0073b9ac5e77f97baf3d59664b bind-9.8.5_P2-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: a8a263ce4cd00596666fe24dcc5c49ef bind-9.8.5_P2-x86_64-1_slack13.37.txz
Slackware 14.0 package: 33044470839cbf0a3948debfec9acc8e bind-9.9.3_P2-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 080e68a54e368d2c19a35004be00c971 bind-9.9.3_P2-x86_64-1_slack14.0.txz
Slackware -current package: 23363bfc2bc8056cade9feca02521ae2 n/bind-9.9.3_P2-i486-1.txz
Slackware x86_64 -current package: 47f3d5dfcc55a467aee082174552c7a4 n/bind-9.9.3_P2-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg bind-9.9.3_P2-i486-1_slack14.0.txz Then, restart the name server: # /etc/rc.d/rc.bind restart