Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 12.10, 12.04 LTS: USN-1783-1 Critical: Bind9 Memory Issue

ubuntu
Calendar Grey March 29, 2013
Scroller Ubuntu
A recently discovered flaw in Bind9 enables malicious actors to disrupt the service through specially designed network requests affecting various versions of Ubuntu.
Bind could be made to consume memory or crash if it received specially crafted network traffic.

Summary

Bind could be made to consume memory or crash if it received specially

crafted network traffic.

Software Description:

- bind9: Internet Domain Name Server

Details:

Matthew Horsfall discovered that Bind incorrectly handled regular

expression checking. A remote attacker could use this flaw to cause Bind to

consume an excessive amount of memory, possibly resulting in a denial of

service. This issue was corrected by disabling RDATA regular expression

syntax checking.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  bind9                           1:9.8.1.dfsg.P1-4.2ubuntu3.2
  libdns81                        1:9.8.1.dfsg.P1-4.2ubuntu3.2

Ubuntu 12.04 LTS:
  bind9                           1:9.8.1.dfsg.P1-4ubuntu0.6
  libdns81                        1:9.8.1.dfsg.P1-4ubuntu0.6

Ubuntu 11.10:
  bind9                           1:9.7.3.dfsg-1ubuntu4.6
  libdns69                        1:9.7.3.dfsg-1ubuntu4.6

Ubuntu 10.04 LTS:
  bind9                           1:9.7.0.dfsg.P1-1ubuntu0.9
  libdns64                        1:9.7.0.dfsg.P1-1ubuntu0.9

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1783-1

CVE-2013-2266

Severity
critical
Lowest
Low
Medium
High
Critical

March 29, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.