Security consultants in NRI Secure Technologies discovered a stack overflow vulnerability in ConnMan, a network manager for embedded devices. An attacker with control of the DNS responses to the DNS proxy in ConnMan might crash the service and, in same cases, remotely execute . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3956-1
Update to the latest upstream version due to security fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-1ab53bf440 2016-02-01 20:30:53.300559 -------------------------------------------------------------------------------- Name : bind Product : Fedora 22 Version : 9.10.3 Release : 8.P3.fc22 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. -------------------------------------------------------------------------------- Update Information: Update to the latest upstream version due to security fixes -------------------------------------------------------------------------------- References: [ 1 ] Bug #1300051 - CVE-2015-8704 CVE-2015-8705 bind: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1300051 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bind' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.