MGASA-2015-0082

Source
https://advisories.mageia.org/MGASA-2015-0082.html
Import Source
https://advisories.mageia.org/MGASA-2015-0082.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0082
Related
Published
2015-02-21T18:03:39Z
Modified
2015-02-21T17:51:08Z
Summary
Updated bind packages fix CVE-2015-1349
Details

Updated bind packages fix security vulnerability:

Jan-Piet Mens discovered that the BIND DNS server would crash when processing an invalid DNSSEC key rollover, either due to an error on the zone operator's part, or due to interference with network traffic by an attacker. This issue affects configurations with the directives "dnssec-lookaside auto;" (as enabled in the Mageia default configuration) or "dnssec-validation auto;" (CVE-2015-1349).

References
Credits

Affected packages

Mageia:4 / bind

Package

Name
bind
Purl
pkg:rpm/mageia/bind?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.9.6.P2-1.mga4

Ecosystem specific

{
    "section": "core"
}