Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Arch Linux Advisory: 2016-01-21 High: Bind Denial Of Service

The package bind before version 9.10.3.P3-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201601-21 ========================================= Severity: High Date : 2016-01-21 CVE-ID : CVE-2015-8704 CVE-2015-8705 Package : bind Type : denial of service Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package bind before version 9.10.3.P3-1 is vulnerable to denial of service. Resolution ========= Upgrade to 9.10.3.P3-1. # pacman -Syu "bind> =9.10.3.P3-1" The problems have been fixed upstream in version 9.10.3.P3. Workaround ========= None. Description ========== - CVE-2015-8704 (denial of service) A buffer size check used to guard against overflow could cause named to exit with an INSIST failure In apl_42.c. A server could exit while performing certain string formatting operations. Examples include (but may not be limited to): 1) Slaves using text-format db files could be vulnerable if receiving a malformed record in a zone transfer from their master. 2) Masters using text-format db files could be vulnerable if they accept a malformed record in a DDNS update message. 3) Recursive resolvers are potentially vulnerable when debug logging, if they are fed a deliberately malformed record by a malicious server. 4) A server which has cached a specially constructed record could encounter this condition while performing 'rndc dumpdb'. - CVE-2015-8705 (denial of service) In versions of BIND 9.10, errors can occur when OPT pseudo-RR data or ECS options are formatted to text. In 9.10.3 through 9.10.3-P2, the issue may result in a REQUIRE assertion failure in buffer.c resulting in application exit. This issue can affect both authoritative and recursive servers if they are performing debug logging. It may also crash related tools which use the same code, such as dig or delv. Impact ===== A remote attacker is able to use specially crafted records that, when processed, are leadingto application crash resulting in denial of service. This issue affects slaves, masters, recursive resolvers as well as related tools which use the same code. References ========= https://access.redhat.com/security/cve/CVE-2015-8704 https://access.redhat.com/security/cve/CVE-2015-8705 https://kb.isc.org/docs/aa-01335 . Urgent notice for Arch Linux users: bind faces a critical remote denial of service vulnerability. Update is strongly advised.. Arch Linux Advisory, Bind Denial Service, High Severity Advisory, Remote Exploit. . LinuxSecurity.com Team

Calendar 2 Jan 21, 2016 ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here