ISC BIND SIG Cached Resource Record Buffer Overflow Vulnerability
BID:6160
Info
ISC BIND SIG Cached Resource Record Buffer Overflow Vulnerability
| Bugtraq ID: | 6160 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1219 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | Discovery of this vulnerability credited to Neel Mehta of ISS X-Force. |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Cobalt RaQ XTR SGI IRIX 6.5.18 SGI IRIX 6.5.17 SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 SCO Open Server 5.0.7 SCO Open Server 5.0.6 SCO Open Server 5.0.5 Openwall Openwall GNU/*/Linux (Owl)-current OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 ISC BIND 8.3.3 ISC BIND 8.3.2 ISC BIND 8.3.1 ISC BIND 8.3 .0 ISC BIND 8.2.6 ISC BIND 8.2.5 ISC BIND 8.2.4 ISC BIND 8.2.3 ISC BIND 8.2.2 ISC BIND 8.2.1 ISC BIND 8.2 ISC BIND 4.9.10 OW2 ISC BIND 4.9.10 ISC BIND 4.9.9 ISC BIND 4.9.8 ISC BIND 4.9.7 ISC BIND 4.9.6 ISC BIND 4.9.5 ISC BIND 4.9.4 ISC BIND 4.9.3 ISC BIND 4.9 HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX 10.24 HP HP-UX 10.20 HP HP-UX 10.10 FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 Compaq Tru64 5.1 b PK1 (BL1) Compaq Tru64 5.1 b Compaq Tru64 5.1 a PK3 (BL3) Compaq Tru64 5.1 a PK2 (BL2) Compaq Tru64 5.1 a PK1 (BL1) Compaq Tru64 5.1 a Compaq Tru64 5.1 PK5 (BL19) Compaq Tru64 5.1 PK4 (BL18) Compaq Tru64 5.1 PK3 (BL17) Compaq Tru64 5.1 Compaq Tru64 5.0 a PK3 (BL17) Compaq Tru64 5.0 a Compaq Tru64 4.0 g PK3 (BL17) Compaq Tru64 4.0 g Compaq Tru64 4.0 f PK7 (BL18) Compaq Tru64 4.0 f PK6 (BL17) Compaq Tru64 4.0 f Astaro Security Linux 3.2 11 Astaro Security Linux 3.2 10 Astaro Security Linux 3.2 00 Astaro Security Linux 2.0 30 Astaro Security Linux 2.0 27 Astaro Security Linux 2.0 26 Astaro Security Linux 2.0 25 Astaro Security Linux 2.0 24 Astaro Security Linux 2.0 23 Astaro Security Linux 2.0 16 Apple Mac OS X 10.2 Apple Mac OS X 10.1 Apple Mac OS X 10.0 |
| Not Vulnerable: |
SGI IRIX 6.5.19 ISC BIND 9.2.1 ISC BIND 9.2 ISC BIND 9.1.3 ISC BIND 9.1.2 ISC BIND 9.1.1 ISC BIND 9.1 ISC BIND 9.0 ISC BIND 8.3.4 ISC BIND 8.2.7 ISC BIND 4.9.11 Astaro Security Linux 3.2 12 |
Exploit / POC
ISC BIND SIG Cached Resource Record Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ISC BIND SIG Cached Resource Record Buffer Overflow Vulnerability
Solution:
Sun have released a security update to address this issue in the RAQ XTR. Please see references section for further details. A fix is linked below.
SCO has released a security advisory to address this issue in OpenServer (CSSA-2003-SCO.17.1). Further information relating to obtaining and applying fixes can be found in the referenced advisory.
HP has released a revised advisory (HPSBUX0208-209(rev.15)) to address this issue in affected HP-UX systems. Customers who are affected by this issue are advised to apply appropriate patches. Further information regarding obtaining and applying patches is available in the referenced advisory.
HP has released an updated advisory HPSBUX0208-209(rev.14) for HP-UX systems. Preliminary updates for HP-UX 11 and 11.11 are available. Further information on obtaining and applying fixes is available in the referenced HP advisory (HPSBUX0208-209).
ISC has stated that new versions of BIND 4 and 8 will be available in the near future. Users are advised to contact ISC for further details. ISC has released patches for some versions.
FreeBSD has released an advisory. Users are advised to update systems to the 4.7-STABLE branch or to the appropriate RELENG_4_x branch dated after the correction date. A patch is also available. Further details on obtaining and applying fixes can be found in the referenced advisory.
EnGarde Secure Linux has released an advisory. Further information about obtaining and applying fixes can be found in the referenced advisory.
SuSE has released an advisory. Updated packages are available. Further information about obtaining and applying fixes can be found in the referenced advisory.
Mandrake has released an advisory (MDKSA-2002:077) containing fix information. Further information about obtaining and applying fixes can be found in the referenced advisory.
Debian has released an advisory (DSA 196-1) containing fix information. Further information about obtaining and applying fixes can be found in the referenced advisory.
Conectiva has released an advisory (CLA-2002:546) containing fix information. Further information about obtaining and applying fixes can be found in the referenced advisory.
OpenPKG has released an advisory containing upgrades for this and other vulnerabilities. OpenPKG 1.0 users are advised to upgrade to the bind-8.2.6-1.0.2 package or later. OpenPKG 1.1 users are advised to upgrade to the bind8-8.3.3-1.1.1 package or later. OpenPKG CURRENT users are advised to upgrade to the bind8-8.3.3-20021114 package or later. bind-9.2.1-1.1.0 packages are also available for OpenPKG 1.1/CURRENT. Further details on obtaining and applying fixes can be found in the attached reference.
This issue is present in Astaro Security Linux versions prior to Up2Date 3.212. Up2Date 3.211 is the minimum version required for users to install Up2Date 3.212.
Trustix Secure Linux has released an advisory. Further details about obtaining and applying fixes can be found in the referenced advisory.
NetBSD has released an advisory. Details about upgrading vulnerable packages through CVS can be found in the referenced advisory.
SGI has released an advisory, and advised vulnerable users to apply patch 4881 to execute the server in a chroot environment. This patch does not fix the vulnerability, but does limit the impact of exploitation. SGI has reported this vulnerability will be fixed in IRIX 6.5.19.
SCO has released an advisory and fixes for OpenLinux (CSSA-2002-059.0). Users are advised to upgrade as soon as possible.
SCO has released a security advisory for UnixWare (CSSA-2003-SCO.2). Information, on obtaining and applying fixes, can be gathered from the reverenced advisory.
Sun recommends disabling recursion if not needed. Patches are available.
Apple has patched this issue in MacOS X versions 10.2.3 and later. See referenced web page for additional details.
Fixes are available:
OpenBSD OpenBSD 3.2
Sun Solaris 8_sparc
OpenBSD OpenBSD 3.0
Sun Cobalt RaQ XTR
Sun Solaris 7.0
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 7.0_x86
OpenBSD OpenBSD 3.1
Sun Solaris 8_x86
HP HP-UX 10.10
HP HP-UX 10.20
HP HP-UX 11.0 4
HP HP-UX 11.0
HP HP-UX 11.11
HP HP-UX 11.22
Compaq Tru64 4.0 f PK6 (BL17)
Compaq Tru64 4.0 f
Compaq Tru64 4.0 g PK3 (BL17)
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f PK7 (BL18)
FreeBSD FreeBSD 4.4
FreeBSD FreeBSD 4.5
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 4.7
ISC BIND 4.9.10
ISC BIND 4.9.7
Compaq Tru64 5.0 a PK3 (BL17)
Compaq Tru64 5.0 a
Compaq Tru64 5.1 b PK1 (BL1)
Compaq Tru64 5.1 a PK1 (BL1)
Compaq Tru64 5.1 a PK2 (BL2)
Compaq Tru64 5.1 PK3 (BL17)
Compaq Tru64 5.1 PK4 (BL18)
Compaq Tru64 5.1 a
Compaq Tru64 5.1
Compaq Tru64 5.1 PK5 (BL19)
Compaq Tru64 5.1 a PK3 (BL3)
Compaq Tru64 5.1 b
ISC BIND 8.2.3
ISC BIND 8.2.4
ISC BIND 8.2.6
Solution:
Sun have released a security update to address this issue in the RAQ XTR. Please see references section for further details. A fix is linked below.
SCO has released a security advisory to address this issue in OpenServer (CSSA-2003-SCO.17.1). Further information relating to obtaining and applying fixes can be found in the referenced advisory.
HP has released a revised advisory (HPSBUX0208-209(rev.15)) to address this issue in affected HP-UX systems. Customers who are affected by this issue are advised to apply appropriate patches. Further information regarding obtaining and applying patches is available in the referenced advisory.
HP has released an updated advisory HPSBUX0208-209(rev.14) for HP-UX systems. Preliminary updates for HP-UX 11 and 11.11 are available. Further information on obtaining and applying fixes is available in the referenced HP advisory (HPSBUX0208-209).
ISC has stated that new versions of BIND 4 and 8 will be available in the near future. Users are advised to contact ISC for further details. ISC has released patches for some versions.
FreeBSD has released an advisory. Users are advised to update systems to the 4.7-STABLE branch or to the appropriate RELENG_4_x branch dated after the correction date. A patch is also available. Further details on obtaining and applying fixes can be found in the referenced advisory.
EnGarde Secure Linux has released an advisory. Further information about obtaining and applying fixes can be found in the referenced advisory.
SuSE has released an advisory. Updated packages are available. Further information about obtaining and applying fixes can be found in the referenced advisory.
Mandrake has released an advisory (MDKSA-2002:077) containing fix information. Further information about obtaining and applying fixes can be found in the referenced advisory.
Debian has released an advisory (DSA 196-1) containing fix information. Further information about obtaining and applying fixes can be found in the referenced advisory.
Conectiva has released an advisory (CLA-2002:546) containing fix information. Further information about obtaining and applying fixes can be found in the referenced advisory.
OpenPKG has released an advisory containing upgrades for this and other vulnerabilities. OpenPKG 1.0 users are advised to upgrade to the bind-8.2.6-1.0.2 package or later. OpenPKG 1.1 users are advised to upgrade to the bind8-8.3.3-1.1.1 package or later. OpenPKG CURRENT users are advised to upgrade to the bind8-8.3.3-20021114 package or later. bind-9.2.1-1.1.0 packages are also available for OpenPKG 1.1/CURRENT. Further details on obtaining and applying fixes can be found in the attached reference.
This issue is present in Astaro Security Linux versions prior to Up2Date 3.212. Up2Date 3.211 is the minimum version required for users to install Up2Date 3.212.
Trustix Secure Linux has released an advisory. Further details about obtaining and applying fixes can be found in the referenced advisory.
NetBSD has released an advisory. Details about upgrading vulnerable packages through CVS can be found in the referenced advisory.
SGI has released an advisory, and advised vulnerable users to apply patch 4881 to execute the server in a chroot environment. This patch does not fix the vulnerability, but does limit the impact of exploitation. SGI has reported this vulnerability will be fixed in IRIX 6.5.19.
SCO has released an advisory and fixes for OpenLinux (CSSA-2002-059.0). Users are advised to upgrade as soon as possible.
SCO has released a security advisory for UnixWare (CSSA-2003-SCO.2). Information, on obtaining and applying fixes, can be gathered from the reverenced advisory.
Sun recommends disabling recursion if not needed. Patches are available.
Apple has patched this issue in MacOS X versions 10.2.3 and later. See referenced web page for additional details.
Fixes are available:
OpenBSD OpenBSD 3.2
-
OpenBSD 005_named.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/005_named.patch
Sun Solaris 8_sparc
-
Sun 109326-10
http://sunsolve.sun.com -
Sun 112970-03
http://sunsolve.sun.com
OpenBSD OpenBSD 3.0
-
OpenBSD 036_named.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/036_named.patch
Sun Cobalt RaQ XTR
-
Sun RaQXTR-All-Security-1.0.1-16311.pkg
http://ftp.cobalt.sun.com/pub/packages/raqxtr/eng/RaQXTR-All-Security- 1.0.1-16311.pkg
Sun Solaris 7.0
-
Sun 106938-07
http://sunsolve.sun.com
Sun Solaris 9
-
Sun 112970-03
http://sunsolve.sun.com
Sun Solaris 9_x86
-
Sun 114354-01
http://sunsolve.sun.com
Sun Solaris 7.0_x86
-
Sun 106939-07
http://sunsolve.sun.com
OpenBSD OpenBSD 3.1
-
OpenBSD 019_named.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/019_named.patch
Sun Solaris 8_x86
-
Sun 109327-10
http://sunsolve.sun.com
HP HP-UX 10.10
-
HP libc.1.1010
ftp://bind:[email protected]/ -
HP libc.a.1010
ftp://bind:[email protected]/ -
HP PHNE_27792.depot
ftp://bind:[email protected]/
HP HP-UX 10.20
-
HP PHCO_26158
http://itrc.hp.com -
HP PHNE_27792.depot
ftp://bind:[email protected]/
HP HP-UX 11.0 4
-
HP PHNE_27881
ftp://bind:[email protected]/ -
HP PHNE_28415
ftp://bind:[email protected]/
HP HP-UX 11.0
-
HP PHNE_27795
ftp://bind:[email protected]/ -
HP PHNE_28449
ftp://bind:[email protected]/
HP HP-UX 11.11
-
HP PHNE_27796
ftp://bind:[email protected]/ -
HP PHNE_28450
ftp://bind:[email protected]/
HP HP-UX 11.22
-
HP PHNE_27842.depot
ftp://bind:[email protected]/ -
HP PHNE_28490
ftp://bind:[email protected]/
Compaq Tru64 4.0 f PK6 (BL17)
-
HP DUV40FB18-C0090600-16637-ES-20030129.tar
Patch Kit PK7 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v4.0f/DUV40FB18-C009 0600-16637-ES-20030129.tar
Compaq Tru64 4.0 f
-
HP DUV40FB18-C0090600-16637-ES-20030129.tar
Patch Kit PK7 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v4.0f/DUV40FB18-C009 0600-16637-ES-20030129.tar
Compaq Tru64 4.0 g PK3 (BL17)
-
HP T64V40GB17-C0028000-16638-ES-20030129.tar
Patch Kit PK3 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v4.0g/T64V40GB17-C00 28000-16638-ES-20030129.tar
Compaq Tru64 4.0 g
-
HP T64V40GB17-C0028000-16638-ES-20030129.tar
Patch Kit PK3 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v4.0g/T64V40GB17-C00 28000-16638-ES-20030129.tar
Compaq Tru64 4.0 f PK7 (BL18)
-
HP DUV40FB18-C0090600-16637-ES-20030129.tar
Patch Kit PK7 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v4.0f/DUV40FB18-C009 0600-16637-ES-20030129.tar
FreeBSD FreeBSD 4.4
-
FreeBSD bind.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:43/bind.patch
FreeBSD FreeBSD 4.5
-
FreeBSD bind.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:43/bind.patch
FreeBSD FreeBSD 4.6
-
FreeBSD bind.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:43/bind.patch
FreeBSD FreeBSD 4.7
-
FreeBSD bind.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:43/bind.patch
ISC BIND 4.9.10
-
ISC bind4910.diff
Source code patch.
http://www.isc.org/products/BIND/patches/bind4910.diff
ISC BIND 4.9.7
-
HP PHCO_27882
s700_800 10.24
ftp://bind:[email protected]/ -
HP PHNE_27879.depot
s700_800 10.24
ftp://bind:[email protected]/
Compaq Tru64 5.0 a PK3 (BL17)
-
HP T64V50AB17-C0031104-16655-ES-20030129.tar
http://ftp.support.compaq.com/patches/public/unix/v5.0a/T64V50AB17-C00 31104-16655-ES-20030129.tar
Compaq Tru64 5.0 a
-
HP T64V50AB17-C0031104-16655-ES-20030129.tar
http://ftp.support.compaq.com/patches/public/unix/v5.0a/T64V50AB17-C00 31104-16655-ES-20030129.tar
Compaq Tru64 5.1 b PK1 (BL1)
-
HP T64V51BB1-C0002700-16642-ES-20030129.tar
Patch Kit PK1 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1b/T64V51BB1-C000 2700-16642-ES-20030129.tar
Compaq Tru64 5.1 a PK1 (BL1)
-
HP T64V51AB3-C0099200-16641-ES-20030129.tar
Patch Kit PK3 is a pre-requisite for this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1a/T64V51AB3-C009 9200-16641-ES-20030129.tar
Compaq Tru64 5.1 a PK2 (BL2)
-
HP T64V51AB3-C0099200-16641-ES-20030129.tar
Patch Kit PK3 is a pre-requisite for this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1a/T64V51AB3-C009 9200-16641-ES-20030129.tar
Compaq Tru64 5.1 PK3 (BL17)
-
HP T64V51B19-C0167700-16640-ES-20030129.tar
Patch Kit PK5 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1/T64V51B19-C0167 700-16640-ES-20030129.tar
Compaq Tru64 5.1 PK4 (BL18)
-
HP T64V51B19-C0167700-16640-ES-20030129.tar
Patch Kit PK5 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1/T64V51B19-C0167 700-16640-ES-20030129.tar
Compaq Tru64 5.1 a
-
HP T64V51AB3-C0099200-16641-ES-20030129.tar
Patch Kit PK3 is a pre-requisite for this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1a/T64V51AB3-C009 9200-16641-ES-20030129.tar
Compaq Tru64 5.1
-
HP T64V51B19-C0167700-16640-ES-20030129.tar
Patch Kit PK5 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1/T64V51B19-C0167 700-16640-ES-20030129.tar
Compaq Tru64 5.1 PK5 (BL19)
-
HP T64V51B19-C0167700-16640-ES-20030129.tar
Patch Kit PK5 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1/T64V51B19-C0167 700-16640-ES-20030129.tar
Compaq Tru64 5.1 a PK3 (BL3)
-
HP T64V51AB3-C0099200-16641-ES-20030129.tar
Patch Kit PK3 is a pre-requisite for this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1a/T64V51AB3-C009 9200-16641-ES-20030129.tar
Compaq Tru64 5.1 b
-
HP T64V51BB1-C0002700-16642-ES-20030129.tar
Patch Kit PK1 is a pre-requisite to this patch.
http://ftp.support.compaq.com/patches/public/unix/v5.1b/T64V51BB1-C000 2700-16642-ES-20030129.tar
ISC BIND 8.2.3
-
Debian bind-dev_8.2.3-0.potato.3_alpha.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind-dev_8.2.3-0.p otato.3_alpha.deb -
Debian bind-dev_8.2.3-0.potato.3_arm.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind-dev_8.2.3-0.p otato.3_arm.deb -
Debian bind-dev_8.2.3-0.potato.3_i386.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind-dev_8.2.3-0.p otato.3_i386.deb -
Debian bind-dev_8.2.3-0.potato.3_m68k.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind-dev_8.2.3-0.p otato.3_m68k.deb -
Debian bind-dev_8.2.3-0.potato.3_powerpc.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind-dev_8.2.3-0.p otato.3_powerpc.deb -
Debian bind-dev_8.2.3-0.potato.3_sparc.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind-dev_8.2.3-0.p otato.3_sparc.deb -
Debian bind-doc_8.2.3-0.potato.3_all.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind-doc_8.2.3-0.p otato.3_all.deb -
Debian bind_8.2.3-0.potato.3_alpha.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind_8.2.3-0.potat o.3_alpha.deb -
Debian bind_8.2.3-0.potato.3_arm.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind_8.2.3-0.potat o.3_arm.deb -
Debian bind_8.2.3-0.potato.3_i386.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind_8.2.3-0.potat o.3_i386.deb -
Debian bind_8.2.3-0.potato.3_m68k.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind_8.2.3-0.potat o.3_m68k.deb -
Debian bind_8.2.3-0.potato.3_powerpc.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind_8.2.3-0.potat o.3_powerpc.deb -
Debian bind_8.2.3-0.potato.3_sparc.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/bind_8.2.3-0.potat o.3_sparc.deb -
Debian dnsutils_8.2.3-0.potato.3_alpha.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/dnsutils_8.2.3-0.p otato.3_alpha.deb -
Debian dnsutils_8.2.3-0.potato.3_arm.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/dnsutils_8.2.3-0.p otato.3_arm.deb -
Debian dnsutils_8.2.3-0.potato.3_i386.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/dnsutils_8.2.3-0.p otato.3_i386.deb -
Debian dnsutils_8.2.3-0.potato.3_m68k.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/dnsutils_8.2.3-0.p otato.3_m68k.deb -
Debian dnsutils_8.2.3-0.potato.3_powerpc.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/dnsutils_8.2.3-0.p otato.3_powerpc.deb -
Debian dnsutils_8.2.3-0.potato.3_sparc.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/dnsutils_8.2.3-0.p otato.3_sparc.deb -
Debian task-dns-server_8.2.3-0.potato.3_all.deb
Debian 2.2 (oldstable).
http://security.debian.org/pool/updates/main/b/bind/task-dns-server_8. 2.3-0.potato.3_all.deb -
S.u.S.E. bind8-8.2.3-121.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/n1/bind8-8.2.3-121.ppc.rpm -
S.u.S.E. bind8-8.2.3-121.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n2/bind8-8.2.3-121.ppc.rpm -
S.u.S.E. bind8-8.2.3-139.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/n1/bind8-8.2.3-139.alpha.rp m -
S.u.S.E. bind8-8.2.3-139.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n2/bind8-8.2.3-139.alpha.rp m -
S.u.S.E. bind8-8.2.3-200.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/n1/bind8-8.2.3-200.i386.rp m -
S.u.S.E. bind8-8.2.3-200.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n2/bind8-8.2.3-200.i386.rp m -
S.u.S.E. bind8-8.2.3-200.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n2/bind8-8.2.3-200.i386.rp m -
S.u.S.E. bind8-devel-8.2.3-200.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n2/bind8-devel-8.2.3-200.i 386.rpm -
S.u.S.E. bind8-devel-8.2.4-200.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n2/bind8-devel-8.2.4-200.pp c.rpm -
S.u.S.E. bind8-devel-8.2.4-261.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n2/bind8-devel-8.2.4-261.i 386.rpm -
S.u.S.E. bindutil-8.2.3-121.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/n1/bindutil-8.2.3-121.ppc.r pm -
S.u.S.E. bindutil-8.2.3-121.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n1/bindutil-8.2.3-121.ppc.r pm -
S.u.S.E. bindutil-8.2.3-139.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/n1/bindutil-8.2.3-139.alpha .rpm -
S.u.S.E. bindutil-8.2.3-139.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n1/bindutil-8.2.3-139.alpha .rpm -
S.u.S.E. bindutil-8.2.3-200.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/n1/bindutil-8.2.3-200.i386 .rpm -
S.u.S.E. bindutil-8.2.3-200.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n1/bindutil-8.2.3-200.i386 .rpm -
S.u.S.E. bindutil-8.2.3-200.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/bindutil-8.2.3-200.i386 .rpm -
SCO bind-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-059.0/R PMS/bind-8.3.4-1.i386.rpm -
SCO bind-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 9.0/RPMS/bind-8.3.4-1.i386.rpm -
SCO bind-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-059.0/RPM S/bind-8.3.4-1.i386.rpm -
SCO bind-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-059. 0/RPMS/bind-8.3.4-1.i386.rpm -
SCO bind-doc-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-059.0/R PMS/bind-doc-8.3.4-1.i386.rpm -
SCO bind-doc-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 9.0/RPMS/bind-doc-8.3.4-1.i386.rpm -
SCO bind-doc-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-059.0/RPM S/bind-doc-8.3.4-1.i386.rpm -
SCO bind-doc-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-059. 0/RPMS/bind-doc-8.3.4-1.i386.rpm -
SCO bind-utils-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-059.0/R PMS/bind-utils-8.3.4-1.i386.rpm -
SCO bind-utils-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-05 9.0/RPMS/bind-utils-8.3.4-1.i386.rpm -
SCO bind-utils-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-059.0/RPM S/bind-utils-8.3.4-1.i386.rpm -
SCO bind-utils-8.3.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-059. 0/RPMS/bind-utils-8.3.4-1.i386.rpm
ISC BIND 8.2.4
-
S.u.S.E. bind8-8.2.4-128.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n2/bind8-8.2.4-128.sparc. rpm -
S.u.S.E. bind8-8.2.4-200.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n2/bind8-8.2.4-200.ppc.rpm -
S.u.S.E. bind8-8.2.4-260.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n2/bind8-8.2.4-260.i386.rp m -
S.u.S.E. bind8-8.2.4-260.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/bind8-8.2.4-260.i 586.rpm -
S.u.S.E. bind8-8.2.4-261.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n2/bind8-8.2.4-261.i386.rp m -
S.u.S.E. bind8-devel-8.2.4-128.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n2/bind8-devel-8.2.4-128. sparc.rpm -
S.u.S.E. bind8-devel-8.2.4-200.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n2/bind8-devel-8.2.4-200.pp c.rpm -
S.u.S.E. bind8-devel-8.2.4-260.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/bind8-devel-8.2.4-260.i 386.rpm -
S.u.S.E. bind8-devel-8.2.4-260.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/bind8-devel-8.2.4 -260.i586.rpm -
S.u.S.E. bind8-devel-8.2.4-261.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n2/bind8-devel-8.2.4-261.i 386.rpm -
S.u.S.E. bindutil-8.2.4-128.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n1/bindutil-8.2.4-128.spa rc.rpm -
S.u.S.E. bindutil-8.2.4-200.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n1/bindutil-8.2.4-200.ppc.r pm -
S.u.S.E. bindutil-8.2.4-260.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n1/bindutil-8.2.4-260.i386 .rpm -
S.u.S.E. bindutil-8.2.4-260.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/bindutil-8.2.4-26 0.i586.rpm -
S.u.S.E. bindutil-8.2.4-261.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n1/bindutil-8.2.4-261.i386 .rpm
ISC BIND 8.2.6
-
Conectiva bind-8.2.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/bind-8.2.6-1U60_2cl.i386. rpm -
Conectiva bind-chroot-8.2.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/bind-chroot-8.2.6-1U60_2c l.i386.rpm -
Conectiva bind-devel-8.2.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/bind-devel-8.2.6-1U60_2cl .i386.rpm -
Conectiva bind-devel-static-8.2.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/bind-devel-static-8.2.6-1 U60_2cl.i386.rpm -
Conectiva bind-doc-8.2.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/bind-doc-8.2.6-1U60_2cl.i 386.rpm -
Conectiva bind-utils-8.2.6-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/bind-utils-8.2.6-1U60_2cl .i386.rpm -
EnGarde Secure Linux bind-chroot-8.2.6-1.0.29.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i386/bind-chroot -8.2.6-1.0.29.i386.rpm -
EnGarde Secure Linux bind-chroot-8.2.6-1.0.29.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i686/bind-chroot -8.2.6-1.0.29.i686.rpm -
EnGarde Secure Linux bind-chroot-utils-8.2.6-1.0.29.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i386/bind-chroot -utils-8.2.6-1.0.29.i386.rpm -
EnGarde Secure Linux bind-chroot-utils-8.2.6-1.0.29.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i686/bind-chroot -utils-8.2.6-1.0.29.i686.rpm -
ISC bind826.diff
Source code patch.
http://www.isc.org/products/BIND/patches/bind826.diff -
Trustix bind-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/bind-8.2.6-2tr.i586 .rpm -
Trustix bind-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/bind-8.2.6-2tr.i586 .rpm -
Trustix bind-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/bind-8.2.6-2tr.i586 .rpm -
Trustix bind-devel-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/bind-devel-8.2.6-2t r.i586.rpm -
Trustix bind-devel-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/bind-devel-8.2.6-2t r.i586.rpm -
Trustix bind-devel-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/bind-devel-8.2.6-2t r.i586.rpm -
Trustix bind-utils-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.1/RPMS/bind-utils-8.2.6-2t r.i586.rpm -
Trustix bind-utils-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.2/RPMS/bind-utils-8.2.6-2t r.i586.rpm -
Trustix bind-utils-8.2.6-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/bind-utils-8.2.6-2t r.i586.rpm
References
ISC BIND SIG Cached Resource Record Buffer Overflow Vulnerability
References:
References:
- BIND Security (ISC)
- CERT Advisory CA-2002-31 Multiple Vulnerabilities in BIND (CERT)
- duv40fb18-c0090600-16637-es-20030129.README (HP)
- ISC BIND Homepage (ISC)
- ISC BIND Patches (ISC)
- Multiple Remote Vulnerabilities in BIND4 and BIND8 (ISS)
- RaQ XTR Patch Page (Sun)
- Sun Alert ID: 48818 (Sun)
- t64v40gb17-c0028000-16638-es-20030129.README (HP)
- t64v50ab17-c0031104-16655-es-20030129.README (HP)
- t64v51ab3-c0099200-16641-es-20030129.README (HP)
- t64v51b19-c0167700-16640-es-20030129.README (HP)
- t64v51bb1-c0002700-16642-es-20030129.README (HP)
- Up2Date 3.212 (Astaro)
- [OpenPKG-SA-2002.011] OpenPKG Security Advisory (bind, bind8) (OpenPKG)