Login
Newsletter
Werbung

Sicherheit: DNS Poisoning in bind
Aktuelle Meldungen Distributionen
Name: DNS Poisoning in bind
ID: TLSA-2007-38
Distribution: TurboLinux
Plattformen: Turbolinux 10 Server, Turbolinux 10 Server x64 Edition, Turbolinux Appliance Server 2.0, Turbolinux 8 Server, Turbolinux Appliance Server 1.0 Hosting Edition, Turbolinux Appliance Server 1.0 Workgroup Edition
Datum: Mi, 1. August 2007, 03:50
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926
Applikationen: BIND

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2007-38
http://www.turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------

Original released date: 31 Jul 2007
Last revised: 31 Jul 2007

Package: bind

Summary: DNS cache poisoning

More information:
Bind includes the named name server, which resolves host names to IP
addresses (and vice versa), and a resolver library (a set of routines
in a system library that provide the interface for programs to use when
accessing domain name services).

BIND generates cryptographically weak DNS query IDs which could allow
a remote attacker to poison DNS caches.

Impact:
The bind allows remote attackers to poison DNS caches.

Affected Products:
- Turbolinux Appliance Server 2.0
- Turbolinux 10 Server x64 Edition
- Turbolinux Appliance Server 1.0 Hosting Edition
- Turbolinux Appliance Server 1.0 Workgroup Edition
- Turbolinux 10 Server
- Turbolinux 8 Server


<Turbolinux Appliance Server 2.0>

Source Packages
Size: MD5

bind-9.2.3-13.src.rpm
3535018 0aadc97759bffd8262567f60a7f1be68

Binary Packages
Size: MD5

bind-9.2.3-13.i586.rpm
371448 6a8b6349412c728d8bad08116a49148e
bind-chroot-9.2.3-13.i586.rpm
9906 44d0fba52bd34ac3f9cc746528d78178
bind-libs-9.2.3-13.i586.rpm
416937 698ff65446b48828d8dfb5c940ad140c
bind-utils-9.2.3-13.i586.rpm
96596 5777bec35f0105651db22f0ae4ba8fb1

<Turbolinux 10 Server x64 Edition>

Source Packages
Size: MD5

bind-9.2.3-13.src.rpm
3535018 8a247a202c452a8b5be2bba53ffa65ce

Binary Packages
Size: MD5

bind-9.2.3-13.x86_64.rpm
398130 2c4a21b36ac463017e545f1a6605a0c5
bind-chroot-9.2.3-13.x86_64.rpm
9835 4334d64999fb24d6e7f45ed0d571b86f
bind-libs-9.2.3-13.x86_64.rpm
518285 dd650dec7f711b6e718a736c7ccc51b0
bind-utils-9.2.3-13.x86_64.rpm
107950 523e2048a2b1412c48ee557b2809f1fb

<Turbolinux Appliance Server 1.0 Hosting Edition>

Source Packages
Size: MD5

bind-9.2.1-7.src.rpm
4980342 e90d17b8566a93be61cd13d9931e68bb

Binary Packages
Size: MD5

bind-9.2.1-7.i586.rpm
2760412 9b2a5be6492fc275c7076d833d069b71
bind-devel-9.2.1-7.i586.rpm
728066 4f764bf8b2887d1cf989b50e733805a2
bind-utils-9.2.1-7.i586.rpm
1719033 4b56803cbdd7ae12cd33a080a837d2e4

<Turbolinux Appliance Server 1.0 Workgroup Edition>

Source Packages
Size: MD5

bind-9.2.1-7.src.rpm
4980342 e72269734e23aae2348881bfb34a687b

Binary Packages
Size: MD5

bind-9.2.1-7.i586.rpm
2760652 049b6a5d6539a2d8410f94b24b232a91
bind-devel-9.2.1-7.i586.rpm
728475 10fad50dc68a22a2483ce0b6ad44e1c1
bind-utils-9.2.1-7.i586.rpm
1719204 0aa93a4bc137bba77bd0e74b24faabd8

<Turbolinux 10 Server>

Source Packages
Size: MD5

bind-9.2.3-13.src.rpm
3535018 0aadc97759bffd8262567f60a7f1be68

Binary Packages
Size: MD5

bind-9.2.3-13.i586.rpm
371448 6a8b6349412c728d8bad08116a49148e
bind-chroot-9.2.3-13.i586.rpm
9906 44d0fba52bd34ac3f9cc746528d78178
bind-libs-9.2.3-13.i586.rpm
416937 698ff65446b48828d8dfb5c940ad140c
bind-utils-9.2.3-13.i586.rpm
96596 5777bec35f0105651db22f0ae4ba8fb1

<Turbolinux 8 Server>

Source Packages
Size: MD5

bind-9.2.1-7.src.rpm
4980342 ffd8e7007d927d69eec2144bdeb42247

Binary Packages
Size: MD5

bind-9.2.1-7.i586.rpm
2761395 08e39df3748f859ec3dcb20b375a7467
bind-devel-9.2.1-7.i586.rpm
729121 6d92c902c82b8ac8b43118f7c622776a
bind-utils-9.2.1-7.i586.rpm
1719314 4928d38cbb473884c7153a2b90b7f7d5


References:

CVE
[CVE-2007-2926]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926

--------------------------------------------------------------------------
Revision History
31 Jul 2007 Initial release
--------------------------------------------------------------------------

Copyright(C) 2007 Turbolinux, Inc. All rights reserved.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFGrs8dK0LzjOqIJMwRAmJjAJ9eK/GJajbG/KtlNT6433L/ywGpBQCeIW4h
0i+/Qhfz7Cu52ct/wf9OBaw=
=en4F
-----END PGP SIGNATURE-----
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung