Mandriva Linux Security Advisory : bind (MDVSA-2015:054)

Medium Nessus Plugin ID 81937


The remote Mandriva Linux host is missing one or more security updates.


Updated bind packages fix security vulnerability :

Jan-Piet Mens discovered that the BIND DNS server would crash when processing an invalid DNSSEC key rollover, either due to an error on the zone operator's part, or due to interference with network traffic by an attacker. This issue affects configurations with the directives 'dnssec-lookaside auto\;' (as enabled in the Mageia default configuration) or 'dnssec-validation auto\;' (CVE-2015-1349).


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 81937

File Name: mandriva_MDVSA-2015-054.nasl

Version: $Revision: 1.4 $

Type: local

Published: 2015/03/19

Modified: 2015/07/19

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:bind, p-cpe:/a:mandriva:linux:bind-devel, p-cpe:/a:mandriva:linux:bind-doc, p-cpe:/a:mandriva:linux:bind-sdb, p-cpe:/a:mandriva:linux:bind-utils, cpe:/o:mandriva:business_server:1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2015/03/04

Reference Information

CVE: CVE-2015-1349

BID: 72673

MDVSA: 2015:054