Security update for bind

SUSE Security Update: Security update for bind
Announcement ID: SUSE-SU-2015:0011-2
Rating: important
References: #743758 #882511 #908994
Affected Products:
  • SUSE Linux Enterprise Server 11 SP2 LTSS

  • An update that solves one vulnerability and has two fixes is now available. It includes one version update.

    Description:


    This update provides bind 9.9.6P1, which fixes a defect in delegation
    handling that could be exploited to crash named. (CVE-2014-8500,
    bsc#908994)

    Additionally, two non-security issues have been fixed:

    * Fix handling of TXT records in ldapdump. (bsc#743758)
    * Fix a multithread issue with IXFR. (bsc#882511)

    Security Issues:

    * CVE-2014-8500

    Indications:

    Everybody should update.

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Linux Enterprise Server 11 SP2 LTSS:
      zypper in -t patch slessp2-bind=10203

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64) [New Version: 9.9.6P1]:
      • bind-9.9.6P1-0.5.5
      • bind-chrootenv-9.9.6P1-0.5.5
      • bind-devel-9.9.6P1-0.5.5
      • bind-doc-9.9.6P1-0.5.5
      • bind-libs-9.9.6P1-0.5.5
      • bind-utils-9.9.6P1-0.5.5
    • SUSE Linux Enterprise Server 11 SP2 LTSS (s390x x86_64) [New Version: 9.9.6P1]:
      • bind-libs-32bit-9.9.6P1-0.5.5

    References:

    • http://support.novell.com/security/cve/CVE-2014-8500.html
    • https://bugzilla.suse.com/743758
    • https://bugzilla.suse.com/882511
    • https://bugzilla.suse.com/908994
    • http://download.suse.com/patch/finder/?keywords=93a0d67b3fb1cddabb9d852b78c4e9a4