First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 233675
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tobias Scherbaum <dertobi123@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 233675 depends on: Show dependency tree
Bug 233675 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-08-02 07:24 0000
BIND 9.4.2-P2 is now available.

This is the SECOND security patch for BIND 9.4.2, addressing
performance and stability issues in BIND 9.4.2-P1.  Key features
are as follows:

- performance improvement over the P1 releases, namely
   + significantly remedying the port allocation issues
   + allowing TCP queries and zone transfers while issuing as many
      outstanding UDP queries as possible
   + additional security of port randomization at the same level as P1

NOTE: There are some remaining stability problems in 9.4.2-P2 when
running under Microsoft Windows.  A fix has been implemented, but
missed the cutoff time for this release; it will be addressed in a
Windows-specific release very soon.


and also 9.5.0:

This is the SECOND security patch for BIND 9.5.0, addressing
performance and stability issues in BIND 9.5.0-P1.  Key features
are as follows:

- performance improvement over the P1 releases, namely
   + significantly remedying the port allocation issues
   + allowing TCP queries and zone transfers while issuing as many
      outstanding UDP queries as possible
   + additional security of port randomization at the same level as P1
- also includes fixes for several bugs in the 9.5.0 base code

NOTE: There are some remaining stability problems in 9.5.0-P2 when
running under Microsoft Windows.  A fix has been implemented, but
missed the cutoff time for this release; it will be addressed in a
Windows-specific release very soon.

Both 9.4.2_p2 and 9.5.0_p2 are inCVS, candidates for stabilization are:
=net-dns/bind-tools-9.4.2_p2
=net-dns/bind-9.4.2_p2

------- Comment #1 From Robert Buchholz 2008-08-02 12:00:35 0000 -------
Arches, please test and mark stable:
=net-dns/bind-9.4.2_p2
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"

------- Comment #2 From Robert Buchholz 2008-08-02 12:01:02 0000 -------
well.. and
=net-dns/bind-tools-9.4.2_p2

as mentioned in comment #0

------- Comment #3 From Tony Vroon 2008-08-02 12:21:14 0000 -------
+  02 Aug 2008; <chainsaw@gentoo.org> bind-9.4.2_p2.ebuild:
+  Stable AMD64 keyword for security bug #233675, tested on Opteron 2218
+  (hardened/amd64, gcc-3.4.6, glibc-2.6.1-r0, 2.6.24-hardened-r3 x86_64) and
+  Opteron 2354 (default/linux/amd64/2008.0/developer, gcc-4.3.1,
+  glibc-2.8_p20080602-r0, 2.6.27-rc1-00154-g660fc1f-dirty x86_64).

+  02 Aug 2008; <chainsaw@gentoo.org> bind-tools-9.4.2_p2.ebuild:
+  Stable AMD64 keyword for security bug #233675, tested on Opteron 2218
+  (hardened/amd64, gcc-3.4.6, glibc-2.6.1-r0, 2.6.24-hardened-r3 x86_64) and
+  Opteron 2354 (default/linux/amd64/2008.0/developer, gcc-4.3.1,
+  glibc-2.8_p20080602-r0, 2.6.27-rc1-00154-g660fc1f-dirty x86_64).

------- Comment #4 From Jeroen Roovers 2008-08-02 16:46:33 0000 -------
Stable for HPPA.

------- Comment #5 From Markus Rothe 2008-08-02 18:26:05 0000 -------
ppc64 stable

------- Comment #6 From Raúl Porcel 2008-08-02 20:04:47 0000 -------
alpha/ia64/sparc/x86 stable

------- Comment #7 From Tobias Scherbaum 2008-08-03 16:05:29 0000 -------
ppc stable and ready for glsa vote.

------- Comment #8 From Pierre-Yves Rofes 2008-08-03 17:42:01 0000 -------
it seems to be more performance than security related... I vote NO.

------- Comment #9 From Robert Buchholz 2008-08-03 18:01:21 0000 -------
According to upstream this issue only affects servers running at >10,000
requests per second, which would be very few installations (and they most
probably monitor upstream mailings anyway), so I vote NO.
closing.

First Last Prev Next    No search results available      Search page      Enter new bug