Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The dns-root-data package contains DNS root zone data as published by IANA to be used as initial source by DNS software. This release adds the DNSKEY record for the KSK-2024 trust anchor. This new key is planned for use starting October 2026, and the previous one (KSK-2017) . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4226-1
Multiple vulnerabilities have been fixed in systemd, the default init system in Debian, when using systemd-resolved with DNSSEC. CVE-2023-7008 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3859-1
Several security vulnerabilities have been discovered in knot-resolver, a caching, DNSSEC-validating DNS resolver which may allow remote attackers to bypass DNSSEC validation or cause a denial-of-service. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3795-1
It was discovered that malformed DNSSEC records within a DNS zone could result in denial of service against Knot Resolver, a caching, DNSSEC- validating DNS resolver. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5633-1
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for pdns-recursor ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:0107-1 Rating: important References: #1121889 Cross-References: CVE-2019-3807 Affected Products: openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for pdns-recursor fixes the following issues: - CVE-2019-3807: Fixed insufficient validation of DNSSEC signatures (boo#1121889) This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-107=1 Package List: - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): pdns-recursor-4.1.2-bp150.2.6.1 References: https://www.suse.com/security/cve/CVE-2019-3807.html https://bugzilla.suse.com/1121889 -- . openSUSE Security Update: Security update for pdns-recursor ________________________________________. update, security, fixes, vulnerability, opensuse. . Severity: Important. LinuxSecurity.com Team
dnsmasq, a DNS forwarder and DHCP server, ships the DNS Root Zone Key Signing Key (KSK), used as the DNSSEC trust anchor. ICANN will rollover the KSK in 11 October 2018, and DNS resolvers will need the new key . Package : dnsmasq Version : 2.72-3+deb8u4 Debian Bug : 907887 dnsmasq, a DNS forwarder and DHCP server, ships the DNS Root Zone Key Signing Key (KSK), used as the DNSSEC trust anchor. ICANN will rollover the KSK in 11 October 2018, and DNS resolvers will need the new key (KSK-2017) to continue performing DNSSEC validation. This dnsmasq package update includes the latest key to prevent issues in scenarios where dnsmasq runs with DNSSEC enabled and it is using the trusted anchors file shipped with the package. Please note this is not the default configuration in Debian. For Debian 8 "Jessie", this problem has been fixed in version 2.72-3+deb8u4. We recommend that you upgrade your dnsmasq packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest dnsmasq update provides crucial enhancements for DNSSEC validation, incorporating a new Key Signing Key for Debian 8. Users are advised to perform an upgrade.. dnsmasq update,dnssec validation,debian packages,key signing,dhcp server. . Severity: Critical. LinuxSecurity.com Team
Updated bind97 packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: bind97 security update Advisory ID: RHSA-2012:1122-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:1122.html Issue date: 2012-07-31 CVE Names: CVE-2012-3817 ==================================================================== 1. Summary: Updated bind97 packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. An uninitialized data structure use flaw was found in BIND when DNSSEC validation was enabled. A remote attacker able to send a large number of queries to a DNSSEC validating BIND resolver could use this flaw to cause it to exit unexpectedly with an assertion failure. (CVE-2012-3817) Users of bind97 are advised to upgrade to these updated packages, which correct this issue. After installing the update, the BIND daemon (named) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your systemhave been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 842897 - CVE-2012-3817 bind: heavy DNSSEC validation load can cause assertion failure 6. Package List: RHEL Desktop Workstation (v. 5 client): Source: i386: bind97-9.7.0-10.P2.el5_8.2.i386.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.i386.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.i386.rpm bind97-devel-9.7.0-10.P2.el5_8.2.i386.rpm bind97-libs-9.7.0-10.P2.el5_8.2.i386.rpm bind97-utils-9.7.0-10.P2.el5_8.2.i386.rpm x86_64: bind97-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.i386.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-devel-9.7.0-10.P2.el5_8.2.i386.rpm bind97-devel-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-libs-9.7.0-10.P2.el5_8.2.i386.rpm bind97-libs-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-utils-9.7.0-10.P2.el5_8.2.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: bind97-9.7.0-10.P2.el5_8.2.i386.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.i386.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.i386.rpm bind97-devel-9.7.0-10.P2.el5_8.2.i386.rpm bind97-libs-9.7.0-10.P2.el5_8.2.i386.rpm bind97-utils-9.7.0-10.P2.el5_8.2.i386.rpm ia64: bind97-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-devel-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-libs-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-utils-9.7.0-10.P2.el5_8.2.ia64.rpm ppc: bind97-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.ppc64.rpm bind97-devel-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-devel-9.7.0-10.P2.el5_8.2.ppc64.rpm bind97-libs-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-libs-9.7.0-10.P2.el5_8.2.ppc64.rpm bind97-utils-9.7.0-10.P2.el5_8.2.ppc.rpm s390x: bind97-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.s390.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-devel-9.7.0-10.P2.el5_8.2.s390.rpm bind97-devel-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-libs-9.7.0-10.P2.el5_8.2.s390.rpm bind97-libs-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-utils-9.7.0-10.P2.el5_8.2.s390x.rpm x86_64: bind97-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.i386.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-devel-9.7.0-10.P2.el5_8.2.i386.rpm bind97-devel-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-libs-9.7.0-10.P2.el5_8.2.i386.rpm bind97-libs-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-utils-9.7.0-10.P2.el5_8.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2012-3817 https://access.redhat.com/security/updates/classification/#important 8. Contact: The RedHat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. . Important notice regarding bind97 regarding a vulnerability within Red Hat Enterprise Linux 5. Immediate upgrade recommended to safeguard against potential threats.. Red Hat Bind97 Security Patch, DNSSEC Update, Linux Security Advisory. . Severity: Important. LinuxSecurity.com Team
Einar Lonn discovered that under certain conditions bind9, a DNS server, may use cached data before initialization. As a result, an attacker can trigger and assertion failure on servers under high query load that do DNSSEC validation. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2517-1
Get the latest Linux and open source security news straight to your inbox.