Slackware: 2020-140-01: bind Security Update

    Date19 May 2020
    58
    Posted ByLinuxSecurity Advisories
    New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
    
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    [slackware-security]  bind (SSA:2020-140-01)
    
    New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to
    fix security issues.
    
    
    Here are the details from the Slackware 14.2 ChangeLog:
    +--------------------------+
    patches/packages/bind-9.11.19-i586-1_slack14.2.txz:  Upgraded.
      This update fixes security issues:
      A malicious actor who intentionally exploits the lack of effective
      limitation on the number of fetches performed when processing referrals
      can, through the use of specially crafted referrals, cause a recursing
      server to issue a very large number of fetches in an attempt to process
      the referral. This has at least two potential effects: The performance of
      the recursing server can potentially be degraded by the additional work
      required to perform these fetches, and the attacker can exploit this
      behavior to use the recursing server as a reflector in a reflection attack
      with a high amplification factor.
      Replaying a TSIG BADTIME response as a request could trigger an assertion
      failure.
      For more information, see:
        https://kb.isc.org/docs/cve-2020-8616
        https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8616
        https://kb.isc.org/docs/cve-2020-8617
        https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8617
      (* Security fix *)
    +--------------------------+
    
    
    Where to find the new packages:
    +-----------------------------+
    
    Thanks to the friendly folks at the OSU Open Source Lab
    (https://osuosl.org) for donating FTP and rsync hosting
    to the Slackware project!  :-)
    
    Also see the "Get Slack" section on https://slackware.com for
    additional mirror sites near you.
    
    Updated package for Slackware 14.0:
    ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/bind-9.11.19-i486-1_slack14.0.txz
    
    Updated package for Slackware x86_64 14.0:
    ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/bind-9.11.19-x86_64-1_slack14.0.txz
    
    Updated package for Slackware 14.1:
    ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/bind-9.11.19-i486-1_slack14.1.txz
    
    Updated package for Slackware x86_64 14.1:
    ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/bind-9.11.19-x86_64-1_slack14.1.txz
    
    Updated package for Slackware 14.2:
    ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/bind-9.11.19-i586-1_slack14.2.txz
    
    Updated package for Slackware x86_64 14.2:
    ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/bind-9.11.19-x86_64-1_slack14.2.txz
    
    Updated package for Slackware -current:
    ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/bind-9.16.3-i586-1.txz
    
    Updated package for Slackware x86_64 -current:
    ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/bind-9.16.3-x86_64-1.txz
    
    
    MD5 signatures:
    +-------------+
    
    Slackware 14.0 package:
    8a8be89119053b4cf308e94c39b0441f  bind-9.11.19-i486-1_slack14.0.txz
    
    Slackware x86_64 14.0 package:
    c1ff5217ff073769862204f708bfc969  bind-9.11.19-x86_64-1_slack14.0.txz
    
    Slackware 14.1 package:
    08b6ff961e66d98a4a3cab7dc6485c83  bind-9.11.19-i486-1_slack14.1.txz
    
    Slackware x86_64 14.1 package:
    28421755e2c614bbfba77ad5d19ed95a  bind-9.11.19-x86_64-1_slack14.1.txz
    
    Slackware 14.2 package:
    3def6c8b8115e1b5eb199281dd7bd6c7  bind-9.11.19-i586-1_slack14.2.txz
    
    Slackware x86_64 14.2 package:
    1533854201484c39c4d6d13a0b0ac246  bind-9.11.19-x86_64-1_slack14.2.txz
    
    Slackware -current package:
    1d0111759a7622d5341a3acb620d42a8  n/bind-9.16.3-i586-1.txz
    
    Slackware x86_64 -current package:
    f22d2d2b35b461bca96df936a65fc4dc  n/bind-9.16.3-x86_64-1.txz
    
    
    Installation instructions:
    +------------------------+
    
    Upgrade the package as root:
    # upgradepkg bind-9.11.19-i586-1_slack14.2.txz
    
    Then, restart the name server:
    
    # /etc/rc.d/rc.bind restart
    
    
    +-----+
    

    LinuxSecurity Poll

    What do you think of the LinuxSecurity Privacy news articles?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/25-what-do-you-think-of-the-linuxsecurity-privacy-news-articles?task=poll.vote&format=json
    25
    radio
    [{"id":"90","title":"Love them!","votes":"90","type":"x","order":"1","pct":78.95,"resources":[]},{"id":"91","title":"I'm indifferent","votes":"18","type":"x","order":"2","pct":15.79,"resources":[]},{"id":"92","title":"Not interested in this topic","votes":"6","type":"x","order":"3","pct":5.26,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.