it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Florian Weimer <fw AT deneb.enyo.de>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 3162-1] bind9 security update
- Date: Wed, 18 Feb 2015 22:22:54 +0100
- List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
- List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
- Old-return-path: <fw AT deneb.enyo.de>
- Priority: urgent
- Resent-date: Wed, 18 Feb 2015 21:23:18 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <oo5xp6pmQ_E.A.YGC.GLQ5UB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-3162-1 security AT debian.org
http://www.debian.org/security/ Florian Weimer
February 18, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : bind9
CVE ID : CVE-2015-1349
Jan-Piet Mens discovered that the BIND DNS server would crash when
processing an invalid DNSSEC key rollover, either due to an error on
the zone operator's part, or due to interference with network traffic
by an attacker. This issue affects configurations with the directives
"dnssec-validation auto;" (as enabled in the Debian default
configuration) or "dnssec-lookaside auto;".
For the stable distribution (wheezy), this problem has been fixed in
version 1:9.8.4.dfsg.P1-6+nmu2+deb7u4.
We recommend that you upgrade your bind9 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iQEcBAEBAgAGBQJU5QqdAAoJEL97/wQC1SS+SyMIAJR6RrvsIhbFjHm863v3YICJ
ijdNPXKLwiaa4UOnPLg1T2TFmuzcGlvwzhq7cIvEHCLan3ebAqTuRQuAbupaekUK
TykDROE7UQDnGBTR28S/EX6c6++oD5BdK8CNLOCtLUfYt/gNJ2LvmW7Nx0rb1M1a
N+JDYlE4T7OuJDrKbRr0UDSMcE0y6oQls1J7PwWl7IYTVoBD02a5sPLpYUcoxkw4
GD1caoOzcIG2MJP1vMxgNYHmnd3Y2BVgI7dGY2bejXQDrDpv6C0ep5jZu3VVbKQA
Qc2T5mdUzl6KAMZ8Gxe6y5WPymoQiw1x3DmaxYfoPHvj4l7UOkKiNBZoJJa9QHA=
=rYbV
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST AT lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster AT lists.debian.org
Archive: 87ioeynccx.fsf AT mid.deneb.enyo.de">https://lists.debian.org/87ioeynccx.fsf AT mid.deneb.enyo.de
- [IT-SecNots] [SECURITY] [DSA 3162-1] bind9 security update, Florian Weimer, 18.02.2015
Archiv bereitgestellt durch MHonArc 2.6.19.