User: Password:
Subscribe / Log in / New account

OpenPKG alert OpenPKG-SA-2007.014 (bind)

From:  OpenPKG GmbH <>
Subject:  [OpenPKG-SA-2007.014] OpenPKG Security Advisory (bind)
Date:  Thu, 17 May 2007 22:47:41 +0200

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ____________________________________________________________________________ Publisher Name: OpenPKG GmbH Publisher Home: Advisory Id (public): OpenPKG-SA-2007.014 Advisory Type: OpenPKG Security Advisory (SA) Advisory Directory: Advisory Document: Advisory Published: 2007-05-17 22:47 UTC Issue Id (internal): OpenPKG-SI-20070517.03 Issue First Created: 2007-05-17 Issue Last Modified: 2007-05-17 Issue Revision: 05 ____________________________________________________________________________ Subject Name: bind Subject Summary: DNS Server Subject Home: Subject Versions: 9.4.* <= 9.4.0 Vulnerability Id: CVE-2007-2241 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: remote network Attack Impact: denial of service Description: As confirmed by the vendor [0], a vulnerability exists in the DNS server BIND [1], version 9.4 up to 9.4.1. A sequence of DNS queries can cause a recursive nameserver to exit and this way cause a Denial of Service (DoS). While it is unlikely these will occur in normal operation, an attack can use them to cause the affected versions to exit. References: [0] [1] [2] ____________________________________________________________________________ Primary Package Name: bind Primary Package Home: Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Community CURRENT bind-9.4.1-20070501 ____________________________________________________________________________ For security reasons, this document was digitally signed with the OpenPGP public key of the OpenPKG GmbH (public key id 61B7AE34) which you can download from or retrieve from the OpenPGP keyserver at hkp:// Follow the instructions at for more details on how to verify the integrity of this document. ____________________________________________________________________________ -----BEGIN PGP SIGNATURE----- Comment: OpenPKG GmbH <> iD8DBQFGTL9oZwQuyWG3rjQRAqwHAKCraAIzFlc/KWzDSLkKLapCRQcxrACglrN9 TkwzSXUTo4CN3q+v/Ncaxyc= =Q0qB -----END PGP SIGNATURE----- ______________________________________________________________________ OpenPKG Announcement List

(Log in to post comments)

Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds