MGASA-2013-0237
Dashboard / Vulnerabilities / MGASA-2013-0237
Summary: Updated bind package fixes security vulnerability
Details: The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (daemon crash) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013 (CVE-2013-4854).
References: https://advisories.mageia.org/MGASA-2013-0237.html, https://bugs.mageia.org/show_bug.cgi?id=10869, https://kb.isc.org/article/AA-01015, https://kb.isc.org/article/AA-01016, https://kb.isc.org/article/AA-01017, http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2013:202/
Affected packages
Package
Name: bind
Purl: pkg:rpm/mageia/bind?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
