[Bluewhite64 Linux Security] bind [BW64SA:20090730-02]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


[Bluewhite64 Linux Security] bind [BW64SA:20090730-02]

New bind packages are available for Bluewhite64 Linux 11.0, 12.0, 12.1 and 12.2
to fix a security issue.

More details about this issue may be found in the Common Vulnerabilities and Exposures
(CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0696

ISC has published an announcement here:

https://www.isc.org/node/479

And CERT has published an advisory here:

http://www.kb.cert.org/vuls/id/725188



Here are the details from the Bluewhite64 Linux 12.2 ChangeLog:
- ----------------------------------------------------------------
PATCHES/packages/bind-9.4.3_P3-x86_64-1.tgz: Upgraded.
This BIND update fixes a security problem where a specially crafted
dynamic update message packet will cause named to exit resulting in
a denial of service.
An active remote exploit is in wide circulation at this time.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0696
https://www.isc.org/node/479
[*** Security fix ***]



Download the new packages from:
- --------------------------------
For Bluewhite64 Linux 11.0:
http://data.bluewhite64.com/bluewhite64-11.0/patches/packages/bind-9.4.3_P3-x86_64-1.tgz

For Bluewhite64 Linux 12.0:
http://data.bluewhite64.com/bluewhite64-12.0/patches/packages/bind-9.4.3_P3-x86_64-1.tgz

For Bluewhite64 Linux 12.1:
http://data.bluewhite64.com/bluewhite64-12.1/patches/packages/bind-9.4.3_P3-x86_64-1.tgz

For Bluewhite64 Linux 12.2:
http://data.bluewhite64.com/bluewhite64-12.2/patches/packages/bind-9.4.3_P3-x86_64-1.tgz


Also, please see the "Get Bluewhite64" section on http://www.bluewhite64.com for
additional mirror sites near you.


MD5 signatures:
- ----------------
Bluewhite64 11.0 package:
878e69f29a2df274f00daad25ff6ae02 bind-9.4.3_P3-x86_64-1.tgz

Bluewhite64 12.0 package:
1c520130dc558bd40d5edf44211a7cbd bind-9.4.3_P3-x86_64-1.tgz

Bluewhite64 12.1 package:
df31b18b57c5954d89df3c4630f8e056 bind-9.4.3_P3-x86_64-1.tgz

Bluewhite64 12.2 package:
3b05aba543ba0a22378b1e8d6d5d6200 bind-9.4.3_P3-x86_64-1.tgz



Installation instructions:
- ---------------------------
Upgrade the package as root:
# upgradepkg bind-9.4.3_P3-x86_64-1.tgz

After the upgrade, if you are running bind, you have to restart the service:

/etc/rc.d/rc.bind restart



- ---
Bluewhite64 Linux Security Team
http://bluewhite64.com/gpg-key

security©bluewhite64.com



- -------------------------------------------------------
To leave the bluewhite64-security mailing list:
Send a blank email to


bluewhite64-security-unsubscribe©bluewhite64.com


You will get a confirmation message back containing
instructions to complete the process.

Please do not reply to this email address.
- -------------------------------------------------------



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkpxr1sACgkQpTOsxuDdlY5DUACdEejpdWdstfT5d9ngnoSWWtWH
8zwAn1WdFRt7rsZr4EwOixxeBHCzzGpR
=nmwu
-----END PGP SIGNATURE-----