The previous version of the PowerDNS Recursor (3.1.5) did not properly address the issue, as UDP source port selection was insufficiently randomized. We advise all users to upgrade to 3.1.6. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory [UPDATE] GLSA 200804-22:03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: PowerDNS Recursor: DNS Cache Poisoning Date: April 18, 2008 Updated: August 21, 2008 Bugs: #215567, #231335 ID: 200804-22:03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Update ===== The previous version of the PowerDNS Recursor (3.1.5) did not properly address the issue, as UDP source port selection was insufficiently randomized. We advise all users to upgrade to 3.1.6. The updated sections appear below. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-dns/pdns-recursor < 3.1.6 > = 3.1.6 Description ========== Amit Klein of Trusteer reported that insufficient randomness is used to calculate the TRXID values and the UDP source port numbers(CVE-2008-1637). Thomas Biege of SUSE pointed out that a prior fix to resolve this issue was incomplete, as it did not always enable the stronger random number generator for source port selection (CVE-2008-3217). Impact ===== A remote attacker could send malicious answers to insert arbitrary DNS data into the cache. These attacks would in turn help an attacker to perform man-in-the-middle and site impersonation attacks. Resolution ========= All PowerDNS Recursor users should upgrade to the latestversion: # emerge --sync # emerge --ask --oneshot --verbose "> =net-dns/pdns-recursor-3.1.6" References ========= [ 1 ] CVE-2008-1637 https://www.cve.org/CVERecord?id=CVE-2008-1637 [ 2 ] CVE-2008-3217 https://www.cve.org/CVERecord?id=CVE-2008-3217 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200804-22 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
New dnsmasq packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, and -current to address possible DNS cache poisoning issues. More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] dnsmasq (SSA:2008-205-01) New dnsmasq packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, and -current to address possible DNS cache poisoning issues. More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CVE-2008-1447 Here are the details from the Slackware 12.1 ChangeLog: +--------------------------+ patches/packages/dnsmasq-2.45-i486-1_slack12.1.tgz: Upgraded to dnsmasq-2.45. It was discovered that earlier versions of dnsmasq have DNS cache weaknesses that are similar to the ones recently discovered in BIND. This new release minimizes the risk of cache poisoning. For more information, see: https://www.cve.org/CVERecord?id=CVE-2008-1447 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/dnsmasq-2.45-i486-1_slack10.0.tgz Updated package for Slackware 10.1: ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/dnsmasq-2.45-i486-1_slack10.1.tgz Updated package for Slackware10.2: ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/dnsmasq-2.45-i486-1_slack10.2.tgz Updated package for Slackware 11.0: ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/dnsmasq-2.45-i486-1_slack11.0.tgz Updated package for Slackware 12.0: ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/dnsmasq-2.45-i486-1_slack12.0.tgz Updated package for Slackware 12.1: ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/dnsmasq-2.45-i486-1_slack12.1.tgz Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 10.0 package: e1f567c3679e23ab3f80a86cec1343c4 dnsmasq-2.45-i486-1_slack10.0.tgz Slackware 10.1 package: aabb7b9b872654b9b663014d49ba37c1 dnsmasq-2.45-i486-1_slack10.1.tgz Slackware 10.2 package: 41c8042baabfdbdeb7b59f2fd48cbc08 dnsmasq-2.45-i486-1_slack10.2.tgz Slackware 11.0 package: fab50ae940bde92eabba0c062908ef42 dnsmasq-2.45-i486-1_slack11.0.tgz Slackware 12.0 package: b8e850a726270c0d7e305a7c6523ede4 dnsmasq-2.45-i486-1_slack12.0.tgz Slackware 12.1 package: 1c61011340f57e4179c788f3f0127dc0 dnsmasq-2.45-i486-1_slack12.1.tgz Slackware -current package: 11fe1505a7177ec1a1c84a1b259b9c03 dnsmasq-2.45-i486-1.tgz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg dnsmasq-2.45-i486-1_slack12.1.tgz Restart dnsmasq: # sh /etc/rc.d/rc.dnsmasq restart +-----+ . Slackware has released critical patch updates for dnsmasq packages, addressing security vulnerabilities tied to DNS cache poisoning. More details are available.. dnsmasq Update, Slackware DNS Security, Cache Poisoning Fix. . Severity: Critical. LinuxSecurity.com Team
New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, and -current to address a security problem. More details may be found at the following links: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] bind (SSA:2008-191-02) New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, and -current to address a security problem. More details may be found at the following links: http://www.kb.cert.org/vuls/id/800113 https://www.cve.org/CVERecord?id=CVE-2008-1447 Here are the details from the Slackware 12.1 ChangeLog: +--------------------------+ patches/packages/bind-9.4.2_P1-i486-1_slack12.1.tgz: Upgraded to bind-9.4.2-P1. This upgrade addresses a security flaw known as the CERT VU#800113 DNS Cache Poisoning Issue. This is the summary of the problem from the BIND site: "A weakness in the DNS protocol may enable the poisoning of caching recurive resolvers with spoofed data. DNSSEC is the only full solution. New versions of BIND provide increased resilience to the attack." It is suggested that sites that run BIND upgrade to one of the new packages in order to reduce their exposure to DNS cache poisoning attacks. For more information, see: http://www.kb.cert.org/vuls/id/800113 https://www.cve.org/CVERecord?id=CVE-2008-1447 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 8.1: Updated packagefor Slackware 9.0: Updated package for Slackware 9.1: Updated package for Slackware 10.0: Updated package for Slackware 10.1: Updated package for Slackware 10.2: Updated package for Slackware 11.0: Updated package for Slackware 12.0: Updated package for Slackware 12.1: Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 8.1 package: c693e1ae4997c7cc23c0051ec1c90796 bind-9.3.5_P1-i386-1_slack8.1.tgz Slackware 9.0 package: 24326f563c6588a0541f3409bc7298cd bind-9.3.5_P1-i386-1_slack9.0.tgz Slackware 9.1 package: 67178dd97006cf4cf3543704c82741b8 bind-9.3.5_P1-i486-1_slack9.1.tgz Slackware 10.0 package: a12c9e8304c5a7e285fa4df7d4b9756b bind-9.3.5_P1-i486-1_slack10.0.tgz Slackware 10.1 package: 6209e4a5f9693451279b0d02795b9bd8 bind-9.3.5_P1-i486-1_slack10.1.tgz Slackware 10.2 package: e1c6d74c787fa3b7f3a5905fef206206 bind-9.3.5_P1-i486-1_slack10.2.tgz Slackware 11.0 package: d354a0118388bb0f3fd32fa79166746a bind-9.3.5_P1-i486-1_slack11.0.tgz Slackware 12.0 package: 5b1087e6a0dc79ebf06144f44d5bb52f bind-9.4.2_P1-i486-1_slack12.0.tgz Slackware 12.1 package: da76550505d62f0d902b710a078d1020 bind-9.4.2_P1-i486-1_slack12.1.tgz Slackware -current package: c255530e46f4cff8080a20b6c8d12443 bind-9.4.2_P1-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg bind-9.4.2_P1-i486-1_slack12.1.tgz Then, restart the nameserver: # /etc/rc.d/rc.bind restart +-----+ . Recent updates to bind packages for Slackware have been released to mitigate significant DNS cache poisoning vulnerabilities and enhance system security.. Slackware BIND Update,DNS Security Fix,Network Services Upgrade. . Severity: Critical. LinuxSecurity.com Team
Amit Klein discovered that the BIND name server generates predictable DNS query IDs, which may lead to cache poisoning attacks. An update for the oldstable distribution (sarge) is in preparation. It will be released soon.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1341-1
Get the latest Linux and open source security news straight to your inbox.