Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Slackware 14.1: 2015-188-04 Critical: Bind Denial Of Service Attack

slackware
Calendar Grey July 8, 2015
Dist Slackware Esm H88
Recent patches for bind packages in Slackware address a significant denial of service vulnerability triggered by harmful queries that obstruct DNSSEC checking.
New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.1 ChangeLog: patches/packages/bind-9.9.7_P1-i486-1_slack14.1.txz: Upgraded. This update fixes a security issue where an attacker who can cause a validating resolver to query a zone containing specifically constructed contents can cause that resolver to fail an assertion and terminate due to a defect in validation code. This means that a recursive resolver that is performing DNSSEC validation can be deliberately stopped by an attacker who can cause the resolver to perform a query against a maliciously-constructed zone. This will result in a denial of service to clients who rely on that resolver. For more information, see: https://kb.isc.org/docs/aa-01267 https://www.cve.org/CVERecord?id=CVE-2015-4620 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 13.0 package: 38e658538037036f3d77108dcf0865c3 bind-9.9.7_P1-i486-1_slack13.0.txz
Slackware x86_64 13.0 package: ce60a95cf08aae43ad371c3344b5ceac bind-9.9.7_P1-x86_64-1_slack13.0.txz
Slackware 13.1 package: 32873005a0cf1fefe87c968dabaa69f7 bind-9.9.7_P1-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: b4660cadd8c2c0db82b63bce019cd425 bind-9.9.7_P1-x86_64-1_slack13.1.txz
Slackware 13.37 package: 60559eab25abe9c4227e786dfbda5ec0 bind-9.9.7_P1-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: 466a456646c4f7a36646d7f802364877 bind-9.9.7_P1-x86_64-1_slack13.37.txz
Slackware 14.0 package: c333a145f504bd7457030e8b8a016ed2 bind-9.9.7_P1-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 79d7fb87a229627e8a48ed2cdfb0b000 bind-9.9.7_P1-x86_64-1_slack14.0.txz
Slackware 14.1 package: 8c5c206b1a1d9ceab53efc04904afcda bind-9.9.7_P1-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 01e296eacac7717a2b42090be480007f bind-9.9.7_P1-x86_64-1_slack14.1.txz
Slackware -current package: ec06a2234cb84ed6509cdc34355a1ca2 n/bind-9.10.2_P2-i486-1.txz
Slackware x86_64 -current package: 7dacb77256d58669f8426a1e0137c4b3 n/bind-9.10.2_P2-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg bind-9.9.7_P1-i486-1_slack14.1.txz Then, restart the name server: # /etc/rc.d/rc.bind restart

Related News

Your message here