Publisher Name: OpenPKG GmbH Publisher Home: http://openpkg.com/ Advisory Id (public): OpenPKG-SA-2002.006 Advisory Type: OpenPKG Security Advisory (SA) Advisory Directory: http://openpkg.com/go/OpenPKG-SA Advisory Document: http://openpkg.com/go/OpenPKG-SA-2002.006 Advisory Published: 2008-11-21 22:59 UTC Issue Id (internal): OpenPKG-SI-20020704.01 Issue First Created: 2002-07-04 Issue Last Modified: 2006-11-28 Issue Revision: 06
Subject Name: BIND Subject Summary: Berkeley Internet Name Domain (BIND) Subject Home: http://www.isc.org/products/BIND/ Subject Versions: * <= 8.2.5 Vulnerability Id: cert:CA-2002-19 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: local system Attack Impact: denial of service Description: According to CERT Advisory CA-2002-19 [5] a buffer overflow vulnerability exists in multiple implementations of DNS resolver libraries. Applications that utilize vulnerable DNS resolver libraries may be affected. For the OpenPKG bind package this means that the included utilities dig, host, nslookup and nsupdate are affected. Please note that the named server itself is not affected. A remote attacker who is able to send malicious DNS responses could potentially exploit this vulnerability to execute arbitrary code or cause a denial of service on a vulnerable system. Note that a possible attack would be performed by a DNS response, thus bypassing any firewall. For more details and background information see the corresponding NetBSD Security Advisory 2002-006 [6]. The Internet Software Consortium (ISC) Berkeley Internet Name Domain (BIND) Vulnerabilities Summary table [7] shows that for the 8.2.x track of BIND the DNS resolver library (libbind) issue is fixed in 8.2.6. References: [1] http://www.openpkg.org/security.html#signature [2] http://www.openpkg.org/tutorial.html#regular-source [3] ftp://ftp.openpkg.org/release/1.0/UPD/ [4] ftp://ftp.openpkg.org/release/1.0/UPD/bind-8.2.6-1.0.1.src.rpm [5] http://www.cert.org/advisories/CA-2002-19.html [6] ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-006.txt.asc [7] http://www.isc.org/products/BIND/bind-security.html
Primary Package Name: bind Primary Package Home: http://openpkg.org/go/package/bind Affected Distribution: Affected Branch: Affected Package: OpenPKG Community 1.0-SOLID bind-8.2.5-1.0.0 Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Community 1.0-SOLID bind-8.2.6-1.0.1