| Summary: | bind - A specially crafted Resource Record could cause named to terminate (CVE-2012-4244) | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Oden Eriksson <oe> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | critical | ||
| Priority: | Normal | CC: | davidwhodgins, luigiwalser, sysadmin-bugs, tmb |
| Version: | 2 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/516075/ | ||
| Whiteboard: | MGA1TOO MGA2-32-OK MGA2-64-OK MGA1-32-OK MGA1-64-OK | ||
| Source RPM: | bind | CVE: | |
| Status comment: | |||
|
Description
Oden Eriksson
2012-09-13 09:19:10 CEST
David Walser
2012-09-13 14:01:54 CEST
CC:
(none) =>
luigiwalser Mandriva has issued an advisory for this today (September 13): http://www.mandriva.com/en/support/security/advisories/?dis=mes5&name=MDVSA-2012:152 Fixed upstream in 9.8.3-P3 and 9.9.1-P3. References (Mageia 1): http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4244 https://kb.isc.org/article/AA-00778 https://kb.isc.org/article/AA-00789 References (Mageia 2): http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4244 https://kb.isc.org/article/AA-00778 https://kb.isc.org/article/AA-00788 Updated packages uploaded for Mageia 1 and Mageia 2. Advisory to come. Package list: bind-9.8.3P3-1.mga1 bind-utils-9.8.3P3-1.mga1 bind-devel-9.8.3P3-1.mga1 bind-doc-9.8.3P3-1.mga1 bind-9.9.1.P3-1.mga2 bind-sdb-9.9.1.P3-1.mga2 bind-utils-9.9.1.P3-1.mga2 bind-devel-9.9.1.P3-1.mga2 bind-doc-9.9.1.P3-1.mga2 from SRPMS: bind-9.8.3P3-1.mga1 bind-9.9.1.P3-1.mga2
David Walser
2012-09-13 21:14:29 CEST
URL:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4244 =>
http://lwn.net/Vulnerabilities/516075/ Advisory: ======================== Updated bind packages fix security vulnerability: A nameserver can be caused to exit with a REQUIRE exception if it can be induced to load a specially crafted resource record (CVE-2012-4244). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4244 https://kb.isc.org/article/AA-00778 https://kb.isc.org/article/AA-00789 https://kb.isc.org/article/AA-00788 http://www.mandriva.com/en/support/security/advisories/?dis=mes5&name=MDVSA-2012:152 ======================== Updated packages in core/updates_testing: ======================== bind-9.8.3P3-1.mga1 bind-utils-9.8.3P3-1.mga1 bind-devel-9.8.3P3-1.mga1 bind-doc-9.8.3P3-1.mga1 bind-9.9.1.P3-1.mga2 bind-sdb-9.9.1.P3-1.mga2 bind-utils-9.9.1.P3-1.mga2 bind-devel-9.9.1.P3-1.mga2 bind-doc-9.9.1.P3-1.mga2 from SRPMS: bind-9.8.3P3-1.mga1.src.rpm bind-9.9.1.P3-1.mga2.src.rpm Assignee:
luigiwalser =>
qa-bugs Testing complete on Mageia 2 i586 and x86-64. Testing using host, dig, and nslookup with the server at 127.0.0.1. Will test Mageia 1 shortly. CC:
(none) =>
davidwhodgins Testing complete on Mageia 1 i586 and x86-64. Could someone from the sysadmin team push the srpm bind-9.9.1.P3-1.mga2.src.rpm from Mageia 2 Core Updates Testing to Core Updates and the srpm bind-9.8.3P3-1.mga1.src.rpm from Mageia 1 Core Updates Testing to Core Updates. Advisory: Updated bind packages fix security vulnerability: A nameserver can be caused to exit with a REQUIRE exception if it can be induced to load a specially crafted resource record (CVE-2012-4244). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4244 https://kb.isc.org/article/AA-00778 https://kb.isc.org/article/AA-00789 https://kb.isc.org/article/AA-00788 http://www.mandriva.com/en/support/security/advisories/?dis=mes5&name=MDVSA-2012:152 https://bugs.mageia.org/show_bug.cgi?id=7469 Keywords:
(none) =>
validated_update Update pushed: https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0269 Status:
NEW =>
RESOLVED |