| |||||||||||||
| ID de Prueba: | 1.3.6.1.4.1.25623.1.0.66597 |
| Categoría: | Debian Local Security Checks |
| Título: | Debian Security Advisory DSA 1963-1 (unbound) |
| Resumen: | Debian Security Advisory DSA 1963-1 (unbound) |
| Descripción: | The remote host is missing an update to unbound announced via advisory DSA 1963-1. It was discovered that Unbound, a DNS resolver, does not properly check cryptographic signatures on NSEC3 records. As a result, zones signed with the NSEC3 variant of DNSSEC lose their cryptographic protection. (An attacker would still have to carry out an ordinary cache poisoning attack to add bad data to the cache.) The old stable distribution (etch) does not contain an unbound package. For the stable distribution (lenny), this problem has been fixed in version 1.0.2-1+lenny1. For the unstable distribution (sid) and the testing distribution (squeeze), this problem has been fixed in version 1.3.4-1. We recommend that you upgrade your unbound package. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%201963-1 |
| Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-3602 http://unbound.net/pipermail/unbound-users/2009-October/000852.html http://www.openwall.com/lists/oss-security/2009/10/09/2 http://www.openwall.com/lists/oss-security/2009/10/09/3 Debian Security Information: DSA-1963 (Google Search) http://www.debian.org/security/2009/dsa-1963 http://osvdb.org/58836 http://secunia.com/advisories/36996 http://secunia.com/advisories/37913 http://www.vupen.com/english/advisories/2009/2875 XForce ISS Database: unbound-nsec3-security-bypass(53729) http://xforce.iss.net/xforce/xfdb/53729 |
| Copyright | Copyright (c) 2009 E-Soft Inc. http://www.securityspace.com |
| Esta es sólo una de 32582 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |
|