This is an old revision of the document!


Slackware64-13.0 ChangeLog (2015-07-28)

Tue Jul 28 19:36:39 UTC 2015

  • patches/packages/bind-9.9.7_P2-x86_64-1_slack13.0.txz
    This update fixes a security issue where an error in the handling of TKEY
    queries can be exploited by an attacker for use as a denial-of-service
    vector, as a constructed packet can use the defect to trigger a REQUIRE
    assertion failure, causing BIND to exit.
    Impact:
    Both recursive and authoritative servers are vulnerable to this defect.
    Additionally, exposure is not prevented by either ACLs or configuration
    options limiting or denying service because the exploitable code occurs
    early in the packet handling, before checks enforcing those boundaries.
    Operators should take steps to upgrade to a patched version as soon as
    possible.
    For more information, see:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5477
    https://kb.isc.org/article/AA-01272
    (* Security fix *)
  • news/2015/07/28/slackware64-13.0-changelog.1438208744.txt.gz
  • Last modified: 9 years ago
  • by Giuseppe Di Terlizzi