Login
Newsletter
Werbung

Sicherheit: Denial of Service in NSD
Aktuelle Meldungen Distributionen
Name: Denial of Service in NSD
ID: FEDORA-2012-11207
Distribution: Fedora
Plattformen: Fedora 16
Datum: Fr, 10. August 2012, 08:00
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2978
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2979
Applikationen: NSD

Originalnachricht

Name        : nsd
Product : Fedora 16
Version : 3.2.13
Release : 1.fc16
URL : http://www.nlnetlabs.nl/nsd/
Summary : Fast and lean authoritative DNS Name Server
Description :
NSD is a complete implementation of an authoritative DNS name server.
For further information about what NSD is and what NSD is not please
consult the REQUIREMENTS document which is a part of this distribution
(thanks to Olaf).

-------------------------------------------------------------------------------
-
Update Information:

Updated upstream releasee for CVE-2012-2979 / VU#517036, our packages were not
vulnerable
Fix for CVE-2012-2978: NSD denial of service vulnerability from non-standard
DNS packet from any host
-------------------------------------------------------------------------------
-
ChangeLog:

* Fri Jul 27 2012 Paul Wouters <pwouters@redhat.com> - 3.2.13-1
- Updated to 3.2.13, addresses VU#517036 CVE-2012-2979
(note Fedora/EPEL packages are not vulnerable to this)
* Thu Jul 19 2012 Paul Wouters <pwouters@redhat.com> - 3.2.12-1
- Upgraded to 3.2.12 which fixes CVE-2012-2978 (rhbz#841268)
* Mon Jul 16 2012 Paul Wouters <pwouters@redhat.com> - 3.2.11-1
- Updated to 3.2.11
- Remove execute perm from unitdir file
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #841268 - CVE-2012-2978: nsd: NSD denial of service vulnerability
from non-standard DNS packet from any host on the internet.
https://bugzilla.redhat.com/show_bug.cgi?id=841268
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update nsd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung