Submitted by KeesCook on Mon, 2007-02-05 12:07
Referenced CVEs:
CVE-2007-0493, CVE-2007-0494
Description:
===========================================================
Ubuntu Security Notice USN-418-1 February 05, 2007
bind9 vulnerabilities
CVE-2007-0493, CVE-2007-0494
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
libdns20 1:9.3.1-2ubuntu1.2
Ubuntu 6.06 LTS:
libdns21 1:9.3.2-2ubuntu1.2
Ubuntu 6.10:
libdns21 1:9.3.2-2ubuntu3.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
A flaw was discovered in Bind's DNSSEC validation code. Remote
attackers could send a specially crafted DNS query which would cause the
Bind server to crash, resulting in a denial of service. Only servers
configured to use DNSSEC extensions were vulnerable.


