Debian-LTS alert DLA-270-1 (bind9)
From: | Santiago Ruano Rincón <santiagorr@riseup.net> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 270-1] bind9 security update | |
Date: | Sat, 11 Jul 2015 17:54:42 +0200 | |
Message-ID: | <20150711155442.GA11763@nomada> |
Package : bind9 Version : 9.7.3.dfsg-1~squeeze15 CVE ID : CVE-2015-4620 Debian Bug : 791715 A vulnerability has been found in the Internet Domain Name Server bind9: CVE-2015-4620 Breno Silveira Soares of Servico Federal de Processamento de Dados (SERPRO) discovered that the BIND DNS server is prone to a denial of service vulnerability. A remote attacker who can cause a validating resolver to query a zone containing specifically constructed contents can cause the resolver to terminate with an assertion failure, resulting in a denial of service to clients relying on the resolver. For the squeeze distribution, these issues have been fixed in version 9.7.3.dfsg-1~squeeze15 of bind9. We recommend that you upgrade your bind9 packages.