[bluewhite64-security] bind (BW64SA:20090116-02)
Hash: SHA1
[bluewhite64-security] bind (BW64SA:20090116-02)
New bind packages are available for Bluewhite64 11.0, 12.0, 12.1,
12.2, and -current to fix a security issue.
More details about this issue may be found here:
https://www.isc.org/node/373
http://www.ocert.org/advisories/ocert-2008-016.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0025
Here are the details from the Bluewhite64 12.2 ChangeLog:
+--------------------------+
PATCHES/packages/bind-9.4.3_P1-x86_64-1.tgz: Upgraded to bind-9.4.3-P1.
Fixed checking on return values from OpenSSL's EVP_VerifyFinal and
DSA_do_verify functions to prevent spoofing answers returned from zones using
the DNSKEY algorithms DSA and NSEC3DSA.
For more information, see:
https://www.isc.org/node/373
http://www.ocert.org/advisories/ocert-2008-016.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0025
[*** Security fix ***]
+--------------------------+
Where to find the new packages:
+-----------------------------+
See the "Get Bluewhite64" section on http://www.bluewhite64.com for additional
mirror sites near you.
Updated package for Bluewhite64 11.0:
http://data.bluewhite64.com/bluewhite64-11.1/patches/packages/bind-9.3.6_P1-x86_64-1.tgz
Updated package for Bluewhite64 12.0:
http://data.bluewhite64.com/bluewhite64-12.0/patches/packages/bind-9.4.3_P1-x86_64-1.tgz
Updated package for Bluewhite64 12.1:
http://data.bluewhite64.com/bluewhite64-12.1/patches/packages/bind-9.4.3_P1-x86_64-1.tgz
Updated package for Bluewhite64 12.2:
http://data.bluewhite64.com/bluewhite64-12.2/patches/packages/bind-9.4.3_P1-x86_64-1.tgz
Updated package for Bluewhite64 -current:
http://data.bluewhite64.com/bluewhite64-current/bluewhite64/n/bind-9.4.3_P1-x86_64-1.tgz
MD5 signatures:
+-------------+
Bluewhite64 11.0 package:
af64da602bd507571c8eb3c12a8ba383 bind-9.3.6_P1-x86_64-1.tgz
Bluewhite64 12.0 package:
ed3a46a015d9feca9d3bf534346d53e1 bind-9.4.3_P1-x86_64-1.tgz
Bluewhite64 12.1 package:
0c8b2f7599988a5b223a5a57e0b7df3e bind-9.4.3_P1-x86_64-1.tgz
Bluewhite64 12.2 package:
c9e9f8d10e2cb2822e9d6002237bff13 bind-9.4.3_P1-x86_64-1.tgz
Bluewhite64 -current package:
c9e9f8d10e2cb2822e9d6002237bff13 bind-9.4.3_P1-x86_64-1.tgz
Installation instructions:
+------------------------+
Upgrade the package as root:
# upgradepkg bind-9.4.3_P1-x86_64-1.tgz
+-----+
Bluewhite64 Linux Security Team
http://bluewhite64.com/gpg-key
security©bluewhite64.com
+-------------------------------------------------------+
| To leave the bluewhite64-security mailing list:
+-------------------------------------------------------+
| Send a blank email to
|
| bluewhite64-security-unsubscribe©bluewhite64.com
|
| You will get a confirmation message back containing
| instructions to complete the process.
|
| Please do not reply to this email address.
+-------------------------------------------------------+
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAklw7h4ACgkQpTOsxuDdlY5liwCeKkpUCO31gv1ePMvhCh8FX0TZ
qiYAn3zdtDHekw9CpcRlaVpFQbsGh03a
=fto6
-----END PGP SIGNATURE-----


