Warning: Undefined array key "advisoryid" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3556145_1edcd913e2b52798c5b9126b8927230e on line 19
______________________________________________________________________________
SuSE Security Announcement
Package: bind8
Announcement-ID: SuSE-SA:2000:45
Date: Thursday, November 16th, 2000 16:00 MEST
Affected SuSE versions: 6.0, 6.1, 6.2, 6.3, 6.4
Vulnerability Type: remote denial of service
Severity (1-10): 7
SuSE default package: no
Other affected systems: all systems using bind, version 8.2.2 before
patchlevel 7
Content of this advisory:
1) security vulnerability resolved: bind8
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
BIND, the Berkeley Internet Name Daemon, versions before 8.2.2p7, has
been found vulnerable to two denial of service attacks: named may crash
after a compressed zone transfer request (ZXFR) and if an SRV record
(defined in RFC2782) is sent to the server. Administrators testing
the ZXFR bug should be aware that it can take several seconds after
the triggering the bug until the nameserver daemon crashes.
SuSE versions 6.0 through 6.4 are affected by these two problems.
The bind8 package in SuSE-7.0 is not affected because a different
version of bind8 (8.2.3) was used in this distribution. By the release
time of the SuSE-7.0 distribution our engineers have determined that
the problems we had with stalling zone transfers under some obscure
conditions were not present with the 8.2.3 release of the package.
Administrators are strongly recommended to upgrade their bind8 package
using the provided packages from the sources below. There is a
temporary fix for the ZXFR problem (disable zone transfers) but none
for the SRV record problem.
For the latest information about security vulnerabilities in the bind
name server consider the Internet Software Consortium bind security
webpage at .
To check if your system has the vulnerable package installed, use the
command `rpm -q
Warning: Undefined array key "block1" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3556145_c1d2d4f425d79c8c327f2b8603847ec6 on line 11
Get the latest Linux and open source security news straight to your inbox.