LWN.net Logo

Mageia alert MGASA-2013-0237 (bind)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2013-0237: Updated bind package fixes security vulnerability
Date:  Mon, 29 Jul 2013 16:02:54 +0200
Message-ID:  <20130729140254.708D443483@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2013-0237 - Updated bind package fixes security vulnerability Publication date: 29 Jul 2013 URL: http://advisories.mageia.org/MGASA-2013-0237.html Type: security Affected Mageia releases: 2, 3 CVE: CVE-2013-4854 Description: The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (daemon crash) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013 (CVE-2013-4854). References: - https://bugs.mageia.org/show_bug.cgi?id=10869 - https://kb.isc.org/article/AA-01015 - https://kb.isc.org/article/AA-01016 - https://kb.isc.org/article/AA-01017 - http://www.mandriva.com/en/support/security/advisories/ad... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4854 SRPMS: - 3/core/bind-9.9.3.P2-1.mga3 - 2/core/bind-9.9.3.P2-1.mga2


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds