Home > Security > Advisories

Advisories

Mandriva Advisories

Package name bind
Date September 10th, 2007
Advisory ID MDKA-2007:090
Affected versions 2007.0, CS4.0, 2007.1
Synopsis Updated bind packages fix numerous bugs

Problem Description

A number of bugs in the BIND9 packages are fixed in this update:

Threading was disabled in the ISC BIND package shipped with Mandriva
Linux 2007 and Corporate Server 4, because the host command did not
work properly with threading enabled. This update only builds the
host command without threading, while the rest of the bind server is
once again SMP-aware.

The bogon ACL was too restrictive and accidentally contained IP
address ranges for some root server networks.

The named daemon is chrooted by default, but logrotate files were
being supplied that served no purpose as named performs it's own
log rotating. The spurious logrotate files have been removed.

The updated packages correct these issues.

Updated Packages

Mandriva Linux 2007

 5f5b456a646c09502fa1f1a22e79f705  2007.0/i586/bind-9.3.2-8.4mdv2007.0.i586.rpm
 68109a31cffb99299f5d86e8283eb69c  2007.0/i586/bind-devel-9.3.2-8.4mdv2007.0.i586.rpm
 313f5d5a93441f89cbe3311b25567698  2007.0/i586/bind-utils-9.3.2-8.4mdv2007.0.i586.rpm 
 5d607d63a5545071fd4a88a176c161b7  2007.0/SRPMS/bind-9.3.2-8.4mdv2007.0.src.rpm

Mandriva Linux 2007/X86_64

 6d6cb7f290836a9793421fcd33716f0f  2007.0/x86_64/bind-9.3.2-8.4mdv2007.0.x86_64.rpm
 a952bc223e57fee48502e5b97be2743f  2007.0/x86_64/bind-devel-9.3.2-8.4mdv2007.0.x86_64.rpm
 252ab1cdc73989059e75cfc59ac22f4c  2007.0/x86_64/bind-utils-9.3.2-8.4mdv2007.0.x86_64.rpm 
 5d607d63a5545071fd4a88a176c161b7  2007.0/SRPMS/bind-9.3.2-8.4mdv2007.0.src.rpm

Corporate Server 4.0

 e33f5aa2a77df749e0023116cc6d4d08  corporate/4.0/i586/bind-9.3.2-7.4.20060mlcs4.i586.rpm
 ffa8492db574bb1eb6a5c8467624a3d1  corporate/4.0/i586/bind-devel-9.3.2-7.4.20060mlcs4.i586.rpm
 49ea6dc6c268ca6ea42d51617faaafe0  corporate/4.0/i586/bind-utils-9.3.2-7.4.20060mlcs4.i586.rpm 
 b8c2d8ddb6c755bf3b9d9ec934a1fbe5  corporate/4.0/SRPMS/bind-9.3.2-7.4.20060mlcs4.src.rpm

Corporate Server 4.0/X86_64

 daba02623a84eda7bda9022646ef2081  corporate/4.0/x86_64/bind-9.3.2-7.4.20060mlcs4.x86_64.rpm
 45b76b901c308c3abdb416d21dcec5d2  corporate/4.0/x86_64/bind-devel-9.3.2-7.4.20060mlcs4.x86_64.rpm
 653be40e5f4b1d85e25a715280ac3a56  corporate/4.0/x86_64/bind-utils-9.3.2-7.4.20060mlcs4.x86_64.rpm 
 b8c2d8ddb6c755bf3b9d9ec934a1fbe5  corporate/4.0/SRPMS/bind-9.3.2-7.4.20060mlcs4.src.rpm

Mandriva Linux 2007.1

 4a50cae7115234cf929d6cc156787b52  2007.1/i586/bind-9.4.1-0.3mdv2007.1.i586.rpm
 c0adc1e58422d1866f1d2c4d2cde8f5e  2007.1/i586/bind-devel-9.4.1-0.3mdv2007.1.i586.rpm
 d70e5f96caf6078597e0f20b5b987b97  2007.1/i586/bind-utils-9.4.1-0.3mdv2007.1.i586.rpm 
 37ef86fe5c05e22adcc119411a907412  2007.1/SRPMS/bind-9.4.1-0.3mdv2007.1.src.rpm

Mandriva Linux 2007.1/X86_64

 ac49e4f46a6621f6ae4ebe4a605df08d  2007.1/x86_64/bind-9.4.1-0.3mdv2007.1.x86_64.rpm
 a83625a06739c1f98c8da7c65fd9a6ab  2007.1/x86_64/bind-devel-9.4.1-0.3mdv2007.1.x86_64.rpm
 26f21c3742a0b99677cc9ef17cfdae14  2007.1/x86_64/bind-utils-9.4.1-0.3mdv2007.1.x86_64.rpm 
 37ef86fe5c05e22adcc119411a907412  2007.1/SRPMS/bind-9.4.1-0.3mdv2007.1.src.rpm

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.