Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.851035
Category:SuSE Local Security Checks
Title:SUSE: Security Advisory for bind (SUSE-SU-2015:0480-1)
Summary:The remote host is missing an update for the 'bind'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'bind'
package(s) announced via the referenced advisory.

Vulnerability Insight:
This bind updated fixes the following two security issues:

*

A flaw in delegation handling could be exploited to put named into
an infinite loop. This has been addressed by placing limits on the number
of levels of recursion named will allow (default 7), and the number of
iterative queries that it will send (default 50) before terminating a
recursive query (CVE-2014-8500, bnc#908994). The recursion depth limit is
configured via the 'max-recursion-depth'
option, and the query limit via the 'max-recursion-queries' option.

*

A flaw when handling malformed NSEC3-signed zones could lead named
to a crash. (CVE-2014-0591, bnc#858639)

Additionally, a non-security bug has been fixed:

* Fix handling of TXT records in ldapdump (bnc#743758).

Security Issues:

* CVE-2014-8500

* CVE-2014-0591

Indications:

Everybody should update.

Affected Software/OS:
bind on SUSE Linux Enterprise Server 11 SP1 LTSS

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-0591
http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html
BugTraq ID: 64801
http://www.securityfocus.com/bid/64801
Debian Security Information: DSA-3023 (Google Search)
http://www.debian.org/security/2014/dsa-3023
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126772.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126761.html
FreeBSD Security Advisory: FreeBSD-SA-14:04
http://www.freebsd.org/security/advisories/FreeBSD-SA-14:04.bind.asc
HPdes Security Advisory: HPSBUX02961
http://marc.info/?l=bugtraq&m=138995561732658&w=2
HPdes Security Advisory: SSRT101420
http://www.mandriva.com/security/advisories?name=MDVSA-2014:002
http://osvdb.org/101973
RedHat Security Advisories: RHSA-2014:0043
http://rhn.redhat.com/errata/RHSA-2014-0043.html
http://www.securitytracker.com/id/1029589
http://secunia.com/advisories/56425
http://secunia.com/advisories/56427
http://secunia.com/advisories/56442
http://secunia.com/advisories/56493
http://secunia.com/advisories/56522
http://secunia.com/advisories/56574
http://secunia.com/advisories/56871
http://secunia.com/advisories/61117
http://secunia.com/advisories/61199
http://secunia.com/advisories/61343
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.524465
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.518391
SuSE Security Announcement: SUSE-SU-2015:0480 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html
SuSE Security Announcement: openSUSE-SU-2014:0199 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-02/msg00016.html
SuSE Security Announcement: openSUSE-SU-2014:0202 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-02/msg00019.html
http://www.ubuntu.com/usn/USN-2081-1
Common Vulnerability Exposure (CVE) ID: CVE-2014-8500
http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html
BugTraq ID: 71590
http://www.securityfocus.com/bid/71590
CERT/CC vulnerability note: VU#264212
http://www.kb.cert.org/vuls/id/264212
Debian Security Information: DSA-3094 (Google Search)
http://www.debian.org/security/2014/dsa-3094
http://security.gentoo.org/glsa/glsa-201502-03.xml
HPdes Security Advisory: HPSBUX03235
http://marc.info/?l=bugtraq&m=142180687100892&w=2
HPdes Security Advisory: HPSBUX03400
http://marc.info/?l=bugtraq&m=144000632319155&w=2
HPdes Security Advisory: SSRT101750
HPdes Security Advisory: SSRT102211
http://www.mandriva.com/security/advisories?name=MDVSA-2015:165
http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.html
NETBSD Security Advisory: NetBSD-SA2015-002
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-002.txt.asc
RedHat Security Advisories: RHSA-2016:0078
http://rhn.redhat.com/errata/RHSA-2016-0078.html
http://securitytracker.com/id?1031311
http://secunia.com/advisories/62064
http://secunia.com/advisories/62122
SuSE Security Announcement: SUSE-SU-2015:0011 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00001.html
SuSE Security Announcement: SUSE-SU-2015:0096 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00017.html
SuSE Security Announcement: SUSE-SU-2015:0488 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00013.html
SuSE Security Announcement: openSUSE-SU-2015:1250 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-07/msg00038.html
http://ubuntu.com/usn/usn-2437-1
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.