LWN.net Logo

bind: validation bypass

Package(s):Bind CVE #(s):CVE-2009-0025
Created:January 9, 2009 Updated:July 30, 2009
Description: From the Red Hat advisory: A flaw was discovered in the way BIND checked the return value of the OpenSSL DSA_do_verify function. On systems using DNSSEC, a malicious zone could present a malformed DSA certificate and bypass proper certificate validation, allowing spoofing attacks.
Alerts:
Fedora FEDORA-2009-8119 2009-07-30
Gentoo 200903-14 2009-03-09
Mandriva MDVSA-2009:037 2008-02-16
CentOS CESA-2009:0020 2009-01-09
Fedora FEDORA-2009-0451 2009-01-14
Ubuntu USN-706-1 2009-01-09
rPath rPSA-2009-0009-1 2009-01-20
Fedora FEDORA-2009-0350 2009-01-14
Debian DSA-1703-1 2009-01-12
Mandriva MDVSA-2009:002 2009-01-09
SuSE SUSE-SA:2009:005 2009-01-22
Slackware SSA:2009-014-02 2009-01-15
Red Hat RHSA-2009:0020-01 2009-01-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds