Sync bind9 1:9.9.5.dfsg-10 (main) from Debian unstable (main)

Bug #1475992 reported by Artur Rona
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
bind9 (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync bind9 1:9.9.5.dfsg-10 (main) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * SECURITY UPDATE: resolver DoS via specially crafted zone data
    - lib/dns/validator.c: don't use uninitialized fixedname.
    - CVE-2015-4620

CVE has been fixed in Debian, as well.

Changelog entries since current wily version 1:9.9.5.dfsg-9ubuntu1:

bind9 (1:9.9.5.dfsg-10) unstable; urgency=high

  * Fix CVE-2015-4620: DNSSEC validation of a malicously crafted zone can
    cause the resolver to crash (closes: #791715).

 -- Michael Gilbert <email address hidden> Thu, 09 Jul 2015 00:43:38 +0000

CVE References

Artur Rona (ari-tczew)
Changed in bind9 (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Robie Basak (racb) wrote :

This bug was fixed in the package bind9 - 1:9.9.5.dfsg-10
Sponsored for Artur Rona (ari-tczew)

---------------
bind9 (1:9.9.5.dfsg-10) unstable; urgency=high

  * Fix CVE-2015-4620: DNSSEC validation of a malicously crafted zone can
    cause the resolver to crash (closes: #791715).

 -- Michael Gilbert <email address hidden> Thu, 09 Jul 2015 00:43:38 +0000

Changed in bind9 (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.