Opened 8 years ago

Closed 8 years ago

Last modified 8 years ago

#7256 closed enhancement (fixed)

bind-9.10.3-P2 (bind9.10.3-P2) and BIND Utilities-9.10.3-P2

Reported by: Fernando de Oliveira Owned by: Fernando de Oliveira
Priority: high Milestone: 7.9
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description (last modified by Fernando de Oliveira)

This is a security update

CVE-2015-3193 (OpenSSL)
CVE-2015-8000
CVE-2015-8461

ftp://ftp.isc.org/isc/bind9/9.10.3-P2/bind-9.10.3-P2.tar.gz

ftp://ftp.isc.org/isc/bind9/9.10.3-P2/bind-9.10.3-P2.tar.gz.sha512.asc

ftp://ftp.isc.org/isc/bind9/9.10.3-P2/CHANGES

ftp://ftp.isc.org/isc/bind9/9.10.3-P2/RELEASE-NOTES-9.10.3-P2.txt

Release Notes for BIND Version 9.10.3-P2

Introduction

This document summarizes changes since BIND 9.10.3:

BIND 9.10.3-P2 addresses the security issues described in CVE-2015-3193
(OpenSSL), CVE-2015-8000 and CVE-2015-8461.

BIND 9.10.3-P1 was incomplete and was withdrawn prior to publication.

Security Fixes

  • Named is potentially vulnerable to the OpenSSL vulnerabilty
    described in CVE-2015-3193.

  • Incorrect reference counting could result in an INSIST failure if a
    socket error occurred while performing a lookup. This flaw is
    disclosed in CVE-2015-8461. [RT#40945]

  • Insufficient testing when parsing a message allowed records with an
    incorrect class to be be accepted, triggering a REQUIRE failure when
    those records were subsequently cached. This flaw is disclosed in
    CVE-2015-8000. [RT #40987]

New Features

  • None. 

Feature Changes

  • Updated the compiled in addresses for H.ROOT-SERVERS.NET. 

Bug Fixes

  • None. 

End of Life

The end of life for BIND 9.10 is yet to be determined but will not be
before BIND 9.12.0 has been released for 6 months.
https://www.isc.org/downloads/software-support-policy/

Change History (4)

comment:1 by Fernando de Oliveira, 8 years ago

Description: modified (diff)

comment:2 by Fernando de Oliveira, 8 years ago

Owner: changed from blfs-book@… to Fernando de Oliveira
Status: newassigned

comment:3 by Fernando de Oliveira, 8 years ago

Resolution: fixed
Status: assignedclosed

Fixed at r16739.

comment:4 by Fernando de Oliveira, 8 years ago

Summary: bind-9.10.3-P2 (bind9.10.3-P2) and BIND Utilities-9.10.3bind-9.10.3-P2 (bind9.10.3-P2) and BIND Utilities-9.10.3-P2
Note: See TracTickets for help on using tickets.