bind-9.3.4-10.P1.3.1AXS3
エラータID: AXSA:2009-360:03
リリース日:
2009/08/04 Tuesday - 16:50
題名:
bind-9.3.4-10.P1.3.1AXS3
影響のあるチャネル:
Asianux Server 3 for x86
Asianux Server 3 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- bind の dns_db_findrdataset 関数には、マスターサーバとして設定されていた場合、リモートの攻撃者が巧妙に作られたダイナミックアップデートパケットによって、サービス拒否 (アサーションの失敗及びデーモンの終了) を引き起こす脆弱性があります。(CVE-2009-0696)
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2009-0696
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.
追加情報:
Update packages.
ダウンロード:
SRPMS
- bind-9.3.4-10.P1.3.1AXS3.src.rpm
MD5: 62dfdb5b40d3946ecec7c36c191f265d
SHA-256: 37e43d3d40f10c5e0fdece494a7d13f2093481125432a1ea96edd26702b9efda
Size: 5.29 MB
Asianux Server 3 for x86
- bind-9.3.4-10.P1.3.1AXS3.i386.rpm
MD5: dee89dfabc419e7fb752c92d7b09cd63
SHA-256: 9c716473120f14d66b6f6ace74bff70de787552b59a9cf5caf25355b15b2a6db
Size: 963.34 kB - bind-chroot-9.3.4-10.P1.3.1AXS3.i386.rpm
MD5: 4da83ffaebf35532a67bbb6e3b9700b3
SHA-256: 911f145ece8f30eda12c3125f6196c9fbcdcf09d8763e6c4446af6a1d1b6b479
Size: 43.31 kB - bind-devel-9.3.4-10.P1.3.1AXS3.i386.rpm
MD5: 46fc9cdbc8852b2da0b92821d24f9b54
SHA-256: 6656fc63366fd8f5720ba27508309bc5080cb39586e48763d8438c205469fd39
Size: 2.58 MB - bind-libs-9.3.4-10.P1.3.1AXS3.i386.rpm
MD5: b76b9a5af3f3414ff9e79daf238160ca
SHA-256: 4f1fc9933d9b34842563208ae6d9c660cbdedca7c12de514e1d055c9b14d252b
Size: 846.27 kB - bind-utils-9.3.4-10.P1.3.1AXS3.i386.rpm
MD5: c39ead8dcab09f8788b216469d468721
SHA-256: f6d3188037f028e2c7cecd0a2cf177343799989782928ba1ca92ead9aedb1ea9
Size: 167.82 kB - caching-nameserver-9.3.4-10.P1.3.1AXS3.i386.rpm
MD5: 07093b3cde98d11e1aeba9e53813866f
SHA-256: b8060a18a10eeeab90146fac9a2f6c2bf1032abc51db0221e5d3c66951e50cd5
Size: 59.76 kB
Asianux Server 3 for x86_64
- bind-9.3.4-10.P1.3.1AXS3.x86_64.rpm
MD5: b58e4060584bd3e9f4b02c55c4df0175
SHA-256: 1456ab1345e31927f20be6c3dd2dc068de6da0bea6a49fcfb5225e3673a20a36
Size: 969.04 kB - bind-chroot-9.3.4-10.P1.3.1AXS3.x86_64.rpm
MD5: cb662eae8bfac613dbcf03ae8fa91827
SHA-256: 83fb4a8a42aac51748ebd3e616bea54320199c5c11755162146d4c7ccacf39dd
Size: 43.28 kB - bind-devel-9.3.4-10.P1.3.1AXS3.x86_64.rpm
MD5: 249775c86ec89f8f69513848537eb19f
SHA-256: 26fc2e9c492c70afd09ca216c678ca3da0317ea8138859471776bbac6afbdaf3
Size: 2.60 MB - bind-libs-9.3.4-10.P1.3.1AXS3.x86_64.rpm
MD5: 96b4857f5f73ebd88325e008810d880e
SHA-256: 754b411166ca9b50da8eb4ea5c013d2f997451384100394255a8c86a3527cb35
Size: 875.95 kB - bind-utils-9.3.4-10.P1.3.1AXS3.x86_64.rpm
MD5: 5a3728114f2bb8c21b7afcb46fadc48e
SHA-256: 5d52c867c925eb9d2d23d5b240a31f2214426e1f97e45f74f55c7ff4e01edeeb
Size: 172.68 kB - caching-nameserver-9.3.4-10.P1.3.1AXS3.x86_64.rpm
MD5: 4ed388098fb01e3982dc660e168d676d
SHA-256: 24dfc53ab033a544c4f069e760ac7ca504ac95b43ce8b0a1d7b862756f0ca6ed
Size: 59.67 kB