diff options
author | erwin <erwin@FreeBSD.org> | 2012-10-10 19:54:44 +0800 |
---|---|---|
committer | erwin <erwin@FreeBSD.org> | 2012-10-10 19:54:44 +0800 |
commit | 443605b92efb48042c56802060b374e08c82226c (patch) | |
tree | 4238bf11294a1261c17aacb56bb70a518ab8d366 /security | |
parent | e2d2e03cf4abd35580f9624fd59b033b9a999446 (diff) | |
download | freebsd-ports-gnome-443605b92efb48042c56802060b374e08c82226c.tar.gz freebsd-ports-gnome-443605b92efb48042c56802060b374e08c82226c.tar.zst freebsd-ports-gnome-443605b92efb48042c56802060b374e08c82226c.zip |
Upgrade to the latest BIND patch level:
A deliberately constructed combination of records could cause named
to hang while populating the additional section of a response.
Security: http://www.vuxml.org/freebsd/57a700f9-12c0-11e2-9f86-001d923933b6.html
Diffstat (limited to 'security')
-rw-r--r-- | security/vuxml/vuln.xml | 38 |
1 files changed, 38 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 6664c7e100d5..c4513a90d7e1 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -51,6 +51,44 @@ Note: Please add new entries to the beginning of this file. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="57a700f9-12c0-11e2-9f86-001d923933b6"> + <topic>dns/bind9* -- crash on deliberately constructed combination of records</topic> + <affects> + <package> + <name>bind99</name> + <range><lt>9.9.1.4</lt></range> + </package> + <package> + <name>bind98</name> + <range><lt>9.8.3.4</lt></range> + </package> + <package> + <name>bind97</name> + <range><lt>9.7.6.4</lt></range> + </package> + <package> + <name>bind96</name> + <range><lt>9.6.3.1.ESV.R7.4</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>ISC reports:</p> + <blockquote cite="https://kb.isc.org/article/AA-00801/"> + <p>A deliberately constructed combination of records could cause named + to hang while populating the additional section of a response.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2012-5166</cvename> + </references> + <dates> + <discovery>2012-09-26</discovery> + <entry>2012-10-10</entry> + </dates> + </vuln> + <vuln vid="e6161b65-1187-11e2-afe3-00262d5ed8ee"> <topic>chromium -- multiple vulnerabilities</topic> <affects> |