===================================================================== CERT-Renater Note d'Information No. 2011/VULN272 _____________________________________________________________________ DATE : 31/03/2011 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Debian version lenny, squeeze, wheezy, sid running bind9. ====================================================================== http://lists.debian.org/debian-security-announce/2011/msg00076.html ______________________________________________________________________ - ------------------------------------------------------------------------- Debian Security Advisory DSA-2208-2 security at debian.org http://www.debian.org/security/ Florian Weimer March 30, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : bind9 Vulnerability : denial of service Problem type : remote Debian-specific: no The BIND, a DNS server, contains a defect related to the processing of new DNSSEC DS records by the caching resolver, which may lead to name resolution failures in the delegated zone. If DNSSEC validation is enabled, this issue can make domains ending in .COM unavailable when the DS record for .COM is added to the DNS root zone on March 31st, 2011. An unpatched server which is affected by this issue can be restarted, thus re-enabling resolution of .COM domains. Configurations not using DNSSEC validations are not affected by this usse. For the oldstable distribution (lenny), this problem has been fixed in version 1:9.6.ESV.R4+dfsg-0+lenny1. We recommend that you upgrade your bind9 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce at lists.debian.org - -- To UNSUBSCRIBE, email to debian-security-announce-REQUEST at lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster at lists.debian.org Archive: http://lists.debian.org/87bp0scsya.fsf@mid.deneb.enyo.de ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================