Slackware 10.0 / 10.1 / 10.2 / 11.0 / 8.1 / 9.0 / 9.1 : bind (SSA:2006-310-01)

medium Nessus Plugin ID 54867

Synopsis

The remote Slackware host is missing a security update.

Description

New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and 11.0 to fix security issues. The minimum OpenSSL version was raised to OpenSSL 0.9.7l and OpenSSL 0.9.8d to avoid exposure to known security flaws in older versions (these patches were already issued for Slackware). If you have not upgraded yet, get those as well to prevent a potentially exploitable security problem in named. In addition, the default RSA exponent was changed from 3 to 65537. Both of these issues are essentially the same as ones discovered in OpenSSL at the end of September 2006, only now there's protection against compiling using the wrong OpenSSL version. RSA keys using exponent 3 (which was previously BIND's default) will need to be regenerated to protect against the forging of RRSIGs.

Solution

Update the affected bind package.

See Also

http://www.nessus.org/u?51d8af47

Plugin Details

Severity: Medium

ID: 54867

File Name: Slackware_SSA_2006-310-01.nasl

Version: 1.11

Type: local

Published: 5/28/2011

Updated: 1/14/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.4

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/o:slackware:slackware_linux:10.1, p-cpe:/a:slackware:slackware_linux:bind, cpe:/o:slackware:slackware_linux:8.1, cpe:/o:slackware:slackware_linux:11.0, cpe:/o:slackware:slackware_linux:9.0, cpe:/o:slackware:slackware_linux:9.1, cpe:/o:slackware:slackware_linux:10.2, cpe:/o:slackware:slackware_linux:10.0

Required KB Items: Host/local_checks_enabled, Host/Slackware/release, Host/Slackware/packages

Exploit Ease: No known exploits are available

Patch Publication Date: 11/7/2006

Vulnerability Publication Date: 9/5/2006

Reference Information

CVE: CVE-2006-4339

BID: 19849

CWE: 310

SSA: 2006-310-01