it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4994-1] bind9 security update
- Date: Thu, 28 Oct 2021 20:30:06 +0000
- Authentication-results: mail02.piratenpartei.de; dkim=none; spf=none (mail02.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/E1mgC2I-0000uy-9i AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=5ji9ZgFerZBA1V9OUjICdCy6/FdBZ9+9Ixn+DoPxsho=; b=pn RQzIJgqp4ilpjUgklkiZ3B8Dli2WjD/xSgp4Qf1sHJUd5hxj0y3CFJtVSFtKvOLJu/cr3xmKCb7Q9 7yiA8Kw9Nt/4xosshVCA9PtsGhH69PbTi//I37ihglMCdzRXiUXtRIWpsapaj/eCbt1nnlO4z5RbV B3qStru1Gha8Ee+lMazW1h7bZygFmsY/nAsX093HCa8+6Mi+za3qIatQqZ8YlX9Ah9wBVtU6b950u d9eecQUjPIshjt5T60Qb7JcHmmk4aZpcnmiIU7iUC5MTkmDRGMlyUxkwAmJDiSm91MkBBaFlhUlk1 4mN5uw6inMl6wpV5N821j3lWV609OHyg==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Thu, 28 Oct 2021 20:30:28 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <CYZsN9rZXkB.A.fsH.jhwehB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4994-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
October 28, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : bind9
CVE ID : CVE-2021-25219
Kishore Kumar Kothapalli discovered that the lame server cache in BIND,
a DNS server implementation, can be abused by an attacker to
significantly degrade resolver performance, resulting in denial of
service (large delays for responses for client queries and DNS timeouts
on client hosts).
For the oldstable distribution (buster), this problem has been fixed
in version 1:9.11.5.P4+dfsg-5.1+deb10u6.
For the stable distribution (bullseye), this problem has been fixed in
version 1:9.16.22-1~deb11u1.
We recommend that you upgrade your bind9 packages.
For the detailed security status of bind9 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/bind9
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmF7B69fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0SW8A/9Eb6aJcW3wekH5ncpTvOnPBrkv4qyzz8+DeVWEZA+z8fIKkrgmOyBjclG
piNtTJUZsFNp7n0FSPtId7AiXsSSDz6xMOSsyHfHEdDrQ/BD+rYJC7VtBRBzdZbD
eXKmMyPg0zz2KFeQ1Bkk6JeL/9BQ1+I+Th9peo1PLfWxCCbzXyzRwxHsktHaKf2q
VbYEFobEzB9TAWW6Z5yC2zJjHTe+816HiHc6s7U8xtTLyfjfu3qmEZf1unFja8Po
+UWNiuqI3bdeuzKeJ2ByRj46RkPM3pekrAO4bjS6Xp4QxXe9n+IJ37tm3CgXSl86
ukBIzA5JYlI53KyHANZOAM4MRSxVCQjU+dbE/KikZEE/F2jpAoFzSxezbinQId6p
My0JdJ7KUQ6omDbXt23fxtQePLCQm47AFs3G/x2JSyTmdq9ZNbvUf6KSKeqe/11g
K13Ip3QcncbFk8sODDxSIY4Add6Jc0Fi56so1j07f+aLty/rlo9/Bo2vc73SoiKl
dkqhtN2nDUhfKvqTLGPz2MfjFO7LbTwRqGb/KQWEyC9Hqyfffk7vVXNgi7cqGAC3
FOtg4ehuORdZJBh3W0Gxw1QUjvJyu7WTGL6l733wxy2gDlRGxLzc+vnwRSjxNNJp
girEEKETk9VV4b0GnlZp1my7Rbp+1V4RDN6JIf3yfvWRd9JvXrw=
=PxZj
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4994-1] bind9 security update, Salvatore Bonaccorso, 28.10.2021
Archiv bereitgestellt durch MHonArc 2.6.24.