See upstream advisory at $URL for more info
@security/maintainer: please double-check if we can move it to C3.
9.9.1-P4 and 9.9.2 have been added but please stabilize bind-9.9.1_p4 for now.
(In reply to comment #2) > 9.9.1-P4 and 9.9.2 have been added but please stabilize bind-9.9.1_p4 for > now. Thanks, Christian. Arches, please test and mark stable.
Stable for HPPA.
x86 done.
amd64 stable
stable ppc ppc64
alpha/arm/ia64/s390/sh/sparc stable
CVE-2012-5166 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5166): ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.
Thanks, everyone. GLSA vote: yes.
Vote: yes. Added to existing GLSA request.
This issue was resolved and addressed in GLSA 201401-34 at http://security.gentoo.org/glsa/glsa-201401-34.xml by GLSA coordinator Sean Amoss (ackle).