Repository 32bit  Forum
Repository 64bit  Wiki

(SSA) bind Print E-mail
Saturday, 05 December 2009
[slackware-security]  bind (SSA:2009-336-01)

New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2,
11.0, 12.0, 12.1, 12.2, 13.0, and -current to fix a security issue.

More details about this issue may be found here:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022
http://www.kb.cert.org/vuls/id/418861


Here are the details from the Slackware 13.0 ChangeLog:
+--------------------------+
Wed Dec 2 20:51:55 UTC 2009
patches/packages/bind-9.4.3_P4-i486-1_slack13.0.txz: Upgraded.
BIND 9.4.3-P4 is a SECURITY PATCH for BIND 9.4.3-P3. It addresses a
potential cache poisoning vulnerability, in which data in the additional
section of a response could be cached without proper DNSSEC validation.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022
http://www.kb.cert.org/vuls/id/418861
(* Security fix *)
+--------------------------+


Where to find the new packages:
+-----------------------------+

HINT: Getting slow download speeds from ftp.slackware.com?
Give slackware.osuosl.org a try. This is another primary FTP site
for Slackware that can be considerably faster than downloading
directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating additional FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 8.1:
bind-9.4.3_P4-i386-1_slack8.1.tgz

Updated package for Slackware 9.0:
bind-9.4.3_P4-i386-1_slack9.0.tgz

Updated package for Slackware 9.1:
bind-9.4.3_P4-i486-1_slack9.1.tgz

Updated package for Slackware 10.0:
bind-9.4.3_P4-i486-1_slack10.0.tgz

Updated package for Slackware 10.1:
bind-9.4.3_P4-i486-1_slack10.1.tgz

Updated package for Slackware 10.2:
bind-9.4.3_P4-i486-1_slack10.2.tgz

Updated package for Slackware 11.0:
bind-9.4.3_P4-i486-1_slack11.0.tgz

Updated package for Slackware 12.0:
bind-9.4.3_P4-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:
bind-9.4.3_P4-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:
bind-9.4.3_P4-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:
bind-9.4.3_P4-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:
bind-9.4.3_P4-x86_64-1_slack13.0.txz

Updated package for Slackware -current:
bind-9.4.3_P4-i486-1.txz

Updated package for Slackware x86_64 -current:
bind-9.4.3_P4-x86_64-1.txz


MD5 signatures:
+-------------+

Slackware 8.1 package:
9de9e38f113552581813e563f558af46 bind-9.4.3_P4-i386-1_slack8.1.tgz

Slackware 9.0 package:
b7102229c23fdbe67861102d5a9cc07e bind-9.4.3_P4-i386-1_slack9.0.tgz

Slackware 9.1 package:
a23619b1d9a4277823c133e02c2e17dd bind-9.4.3_P4-i486-1_slack9.1.tgz

Slackware 10.0 package:
41c019668b1cd93d4990c1c0a37871f3 bind-9.4.3_P4-i486-1_slack10.0.tgz

Slackware 10.1 package:
571af94b9ca6fa6270002a4ac2efd1a5 bind-9.4.3_P4-i486-1_slack10.1.tgz

Slackware 10.2 package:
9c0ebc0c1f17e3eb0bf3a34f748f6bea bind-9.4.3_P4-i486-1_slack10.2.tgz

Slackware 11.0 package:
4ab62ea68d43b85446590208530e6083 bind-9.4.3_P4-i486-1_slack11.0.tgz

Slackware 12.0 package:
05f4975b7915f38064772a5f8e32efac bind-9.4.3_P4-i486-1_slack12.0.tgz

Slackware 12.1 package:
7ae7259553108750e56bac592230d714 bind-9.4.3_P4-i486-1_slack12.1.tgz

Slackware 12.2 package:
94a40d14be8c76829d302d4e8b399ded bind-9.4.3_P4-i486-1_slack12.2.tgz

Slackware 13.0 package:
0ec5ee211c88e64d2db7406d37a76cde bind-9.4.3_P4-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:
0889c8db7e6988809d52465cd60727fd bind-9.4.3_P4-x86_64-1_slack13.0.txz

Slackware -current package:
cda70d71d2fbc98338b5e7852b63abee bind-9.4.3_P4-i486-1.txz

Slackware x86_64 -current package:
f3b06522e828788b40d3811910ba272f bind-9.4.3_P4-x86_64-1.txz


Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg bind-9.4.3_P4-i486-1_slack13.0.txz

Then, restart BIND.


+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it
 
< Prev   Next >
We have 9 guests online

Official Mirror

Darkstar (193.136.198.175), the portuguese open source software mirror, an Intel Core 2 Duo E6700 @ 2.66GHz with 4GiB RAM and 1.5TiB HDD (5x320GB RAID-5), powered by Slackware Linux and running vsftpd, Apache and rsync. This server is maintained by Secção DigitalAEIST in IST, Lisbon, Portugal, and is publicly available through FTP, HTTP and RSYNC protocols at 1Gbit/s.