bind-9.7.3-2.2.0.1.AXS4.P3

エラータID: AXSA:2011-406:01

リリース日: 
2011/12/28 Wednesday - 19:15
題名: 
bind-9.7.3-2.2.0.1.AXS4.P3
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.
Security issues fixed with this release:
CVE-2011-1910
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
CVE-2011-2464
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
Fixed bugs:
- bind on 64-bit PowerPC architecture now uses the same native atomic operations as the PowerPC architecture instead of emulated ones.
- the bind package used to generate the /etc/rndc.key file, by using entropy from /dev/random; this could lead to the bind package installation to hang. Since the rndc.key is used by rndc for advanced administration commands, it is no longer generated automatically during the bind package installation. If needed, users can generate the key file with the rndc-confgen -a command.
- named could sometimes enter a deadlock. This has been fixed.
- If the connection failed during named_sdb startup, the named_sdb PostgreSQL database backend failed to reconnect to the database. It now writes error message the systemlog and retries to connect at every lookup.
- removed conflicts between i686 and x86_64 versions of bind-devel, they can now both be installed on the same machine.
- initscripts does not kill all processes with the name 'named' when stopping the named daemon anymore, only the selected ones.
- added the return codes of the dig utility to the dig man page.
- updated the named.8 manpage to reflect that the system-config-bind utility is not provided anymore.
- the status action of the named initscript would not complete when bind-sdb package was installed. This has been fixed.
- if the resolv.conf contained search keyword with no arguments, the host/nslookup/dig utilities failed to parse correctly. They now ignore those lines.
- Removed the incomplete list of TSIG algorithms from the nsupdate man page. It can be found in the dnssec-keygen man page.
Enhancements:
- re-based to version 9.7.3.
- the host utility now honors debug, attempts and timeout options in resolv.conf.
- added the new option DISABLE_ZONE_CHECKING to /etc/sysconfig/named. This is to bypass zone validation via the named-checkzone utility in initscript and allows to start named with misconfigured zones.
- with this update, size, MD5 and the modification time of /etc/sysconfig/named configuration file is no longer checked via the rpm -V bind command.
- Root zone DNSKEY is now included in the bind package, in the /etc/named.root.key file.

解決策: 

Update packages.

追加情報: 

From Asianux Server 4 SP1.

ダウンロード: 

SRPMS
  1. bind-9.7.3-2.2.0.1.AXS4.P3.src.rpm
    MD5: 1f91e5f657e48ccf6b9df5c15f834ec1
    SHA-256: 79be3722462d0b0d50575e9d945aee89722360c91b88d8c39175f0785a0c411b
    Size: 7.32 MB

Asianux Server 4 for x86
  1. bind-9.7.3-2.2.0.1.AXS4.P3.i686.rpm
    MD5: e820ce47df4c68bc889ca9e8e91bd27f
    SHA-256: 396a7c3739743a37e4ed386440c497ab4e6fcd3b54087ee04e6ee12170dbbcd3
    Size: 3.90 MB
  2. bind-libs-9.7.3-2.2.0.1.AXS4.P3.i686.rpm
    MD5: b2816ffe63e26845cc251916813297e7
    SHA-256: 3257f984ba36bf6a600710ee603e170e229e9bbe47920beb361ec3604893f2c6
    Size: 848.30 kB
  3. bind-utils-9.7.3-2.2.0.1.AXS4.P3.i686.rpm
    MD5: 4a2ce9ac9722032556892e7002424826
    SHA-256: 78bdc1193e0fe4aec2ee4413155f885005598dbad3c0d6d98ccf1282020cfa54
    Size: 175.71 kB
  4. bind-chroot-9.7.3-2.2.0.1.AXS4.P3.i686.rpm
    MD5: 210f0f687c4200bc34a705de2e8d27e1
    SHA-256: a63dcb20c56582d3ca409087ac6a825a46014cd96f100068e71a969dc10a3801
    Size: 66.38 kB

Asianux Server 4 for x86_64
  1. bind-9.7.3-2.2.0.1.AXS4.P3.x86_64.rpm
    MD5: 487e403423d0403685142e536ea03144
    SHA-256: 99e8c40cf555186037181f85fb7a2f8bc5e20a78e0124b69583e512b786e1a04
    Size: 3.89 MB
  2. bind-libs-9.7.3-2.2.0.1.AXS4.P3.x86_64.rpm
    MD5: 1820c2d2fa2c902a33f00f780edfe84f
    SHA-256: 845316c88b9a7b142be894f0c47d55e5ed6ece0138a57b8376b2946c08e25635
    Size: 837.68 kB
  3. bind-utils-9.7.3-2.2.0.1.AXS4.P3.x86_64.rpm
    MD5: 3046ff768d3f32cd2183fb4deb67b1ce
    SHA-256: 4d9f4cd1db326e4d985c7371bd4617b44f8ffb4cd41dba63bfefeda3b5fafcf7
    Size: 176.42 kB
  4. bind-chroot-9.7.3-2.2.0.1.AXS4.P3.x86_64.rpm
    MD5: 0401cc8f223c612a56f0598bcd5fa30a
    SHA-256: fbb66fc409d710099625b2573d5289dcef3499f5671d81d1edb68ffd517e9e09
    Size: 65.93 kB
  5. bind-libs-9.7.3-2.2.0.1.AXS4.P3.i686.rpm
    MD5: b2816ffe63e26845cc251916813297e7
    SHA-256: 3257f984ba36bf6a600710ee603e170e229e9bbe47920beb361ec3604893f2c6
    Size: 848.30 kB