OpenPKG Corporation
OpenPKG CorporationSecuritySecurity Advisories

OpenPKG Security Advisory

OpenPKG-SA-2002.006

Publisher Name:          OpenPKG GmbH
Publisher Home:          http://openpkg.com/

Advisory Id (public):    OpenPKG-SA-2002.006
Advisory Type:           OpenPKG Security Advisory (SA)
Advisory Directory:      http://openpkg.com/go/OpenPKG-SA
Advisory Document:       http://openpkg.com/go/OpenPKG-SA-2002.006
Advisory Published:      2009-07-04 05:56 UTC

Issue Id (internal):     OpenPKG-SI-20020704.01
Issue First Created:     2002-07-04
Issue Last Modified:     2006-11-28
Issue Revision:          06


Subject Name: BIND Subject Summary: Berkeley Internet Name Domain (BIND) Subject Home: http://www.isc.org/products/BIND/ Subject Versions: * <= 8.2.5 Vulnerability Id: cert:CA-2002-19 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: local system Attack Impact: denial of service Description: According to CERT Advisory CA-2002-19 [5] a buffer overflow vulnerability exists in multiple implementations of DNS resolver libraries. Applications that utilize vulnerable DNS resolver libraries may be affected. For the OpenPKG bind package this means that the included utilities dig, host, nslookup and nsupdate are affected. Please note that the named server itself is not affected. A remote attacker who is able to send malicious DNS responses could potentially exploit this vulnerability to execute arbitrary code or cause a denial of service on a vulnerable system. Note that a possible attack would be performed by a DNS response, thus bypassing any firewall. For more details and background information see the corresponding NetBSD Security Advisory 2002-006 [6]. The Internet Software Consortium (ISC) Berkeley Internet Name Domain (BIND) Vulnerabilities Summary table [7] shows that for the 8.2.x track of BIND the DNS resolver library (libbind) issue is fixed in 8.2.6. References: [1] http://www.openpkg.org/security.html#signature [2] http://www.openpkg.org/tutorial.html#regular-source [3] ftp://ftp.openpkg.org/release/1.0/UPD/ [4] ftp://ftp.openpkg.org/release/1.0/UPD/bind-8.2.6-1.0.1.src.rpm [5] http://www.cert.org/advisories/CA-2002-19.html [6] ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-006.txt.asc [7] http://www.isc.org/products/BIND/bind-security.html
Primary Package Name: bind Primary Package Home: http://openpkg.org/go/package/bind Affected Distribution: Affected Branch: Affected Package: OpenPKG Community 1.0-SOLID bind-8.2.5-1.0.0 Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Community 1.0-SOLID bind-8.2.6-1.0.1

Latest Advisories:
2007.023 perl
2007.022 bind
2007.021 wordpress
2007.020 php
2007.019 php
2007.018 freetype
2007.017 ratbox
2007.016 gd
2007.015 quagga
2007.014 bind
more...

See Also:
OpenPKG Enterprise 1
ChangeLog!

Validation: XHTML | CSS