Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1963-1] New unbound packages fix DNSSEC validation (1/2

    From Florian Weimer@1:229/2 to All on Wed Dec 23 21:40:02 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1963-1 [email protected] http://www.debian.org/security/ Florian Weimer December 23, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : unbound
    Vulnerability : cryptographic implementation error
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2009-3602

    It was discovered that Unbound, a DNS resolver, does not properly
    check cryptographic signatures on NSEC3 records. As a result, zones
    signed with the NSEC3 variant of DNSSEC lose their cryptographic
    protection. (An attacker would still have to carry out an ordinary
    cache poisoning attack to add bad data to the cache.)

    The old stable distribution (etch) does not contain an unbound
    package.

    For the stable distribution (lenny), this problem has been fixed in
    version 1.0.2-1+lenny1.

    For the unstable distribution (sid) and the testing distribution
    (squeeze), this problem has been fixed in version 1.3.4-1.

    We recommend that you upgrade your unbound package.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2.orig.tar.gz
    Size/MD5 checksum: 3597275 01b08a9c0d24be981de64b6e4e25ecbe
    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1.diff.gz
    Size/MD5 checksum: 11066 b003007bc954f8877791de9e22c3c146
    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1.dsc
    Size/MD5 checksum: 1436 9e83801b9223c4ac8535243f880044a8

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/u/unbound/libunbound-dev_1.0.2-1+lenny1_alpha.deb
    Size/MD5 checksum: 320244 9482874b056753f0082025d8735643f5
    http://security.debian.org/pool/updates/main/u/unbound/unbound-host_1.0.2-1+lenny1_alpha.deb
    Size/MD5 checksum: 12738 034c9f659508551082c0411307b9c502
    http://security.debian.org/pool/updates/main/u/unbound/libunbound0_1.0.2-1+lenny1_alpha.deb
    Size/MD5 checksum: 215888 4cd1a8ae7cfb61d917b99267746f1877
    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1_alpha.deb
    Size/MD5 checksum: 381560 d89de99e20d73980efb5031fe70f06ff

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/u/unbound/libunbound0_1.0.2-1+lenny1_amd64.deb
    Size/MD5 checksum: 200256 a7c7cd577f7271a63abac791dbf1469b
    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1_amd64.deb
    Size/MD5 checksum: 358126 86bab87ab0f5d5cdb94057dc9bc4ea2d
    http://security.debian.org/pool/updates/main/u/unbound/unbound-host_1.0.2-1+lenny1_amd64.deb
    Size/MD5 checksum: 12266 babd3fec31c85a5ff91080e44504a4cf
    http://security.debian.org/pool/updates/main/u/unbound/libunbound-dev_1.0.2-1+lenny1_amd64.deb
    Size/MD5 checksum: 235494 e7e814a39e5524c8e64134cdbfd4dce9

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/u/unbound/unbound-host_1.0.2-1+lenny1_arm.deb
    Size/MD5 checksum: 11892 139bd5b0186a6187c6a8283330bff6ae
    http://security.debian.org/pool/updates/main/u/unbound/libunbound0_1.0.2-1+lenny1_arm.deb
    Size/MD5 checksum: 179624 44c9d6c40987ea1d02f70615f4bf1d6d
    http://security.debian.org/pool/updates/main/u/unbound/libunbound-dev_1.0.2-1+lenny1_arm.deb
    Size/MD5 checksum: 210562 c81ae06d74c86ca42d85481065fa7133
    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1_arm.deb
    Size/MD5 checksum: 334640 f5693d14213e4118eec1b93d29e13e2f

    armel architecture (ARM EABI)

    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1_armel.deb
    Size/MD5 checksum: 331972 00e1c301c73ea80752c6d2f93e3ac521
    http://security.debian.org/pool/updates/main/u/unbound/libunbound0_1.0.2-1+lenny1_armel.deb
    Size/MD5 checksum: 178740 f39e019eee3b4c54380d9a065f9a2621
    http://security.debian.org/pool/updates/main/u/unbound/unbound-host_1.0.2-1+lenny1_armel.deb
    Size/MD5 checksum: 11850 0726a83164dee4ee7abac8101249bf1a
    http://security.debian.org/pool/updates/main/u/unbound/libunbound-dev_1.0.2-1+lenny1_armel.deb
    Size/MD5 checksum: 209640 904f538ef4d6c3b2ee199c255fd7bbc5

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/u/unbound/libunbound0_1.0.2-1+lenny1_hppa.deb
    Size/MD5 checksum: 207560 af33e156e79347ed6d7b791b4f257524
    http://security.debian.org/pool/updates/main/u/unbound/libunbound-dev_1.0.2-1+lenny1_hppa.deb
    Size/MD5 checksum: 260268 27d99bddc430f56a283897bbfbbbbafe
    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1_hppa.deb
    Size/MD5 checksum: 377250 8887398b373794cdbe669c2ecf41ad39
    http://security.debian.org/pool/updates/main/u/unbound/unbound-host_1.0.2-1+lenny1_hppa.deb
    Size/MD5 checksum: 12810 d5686532a7612faaf4b1de58957bb7c4

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/u/unbound/unbound-host_1.0.2-1+lenny1_i386.deb
    Size/MD5 checksum: 11938 0431937c6253cedf452ddb0227f93cb2
    http://security.debian.org/pool/updates/main/u/unbound/libunbound0_1.0.2-1+lenny1_i386.deb
    Size/MD5 checksum: 186228 9e1c7aa0b3b5c43435a0a3d402ddc062
    http://security.debian.org/pool/updates/main/u/unbound/libunbound-dev_1.0.2-1+lenny1_i386.deb
    Size/MD5 checksum: 207836 933044378c345e44d57b95ae6aaebee5
    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1_i386.deb
    Size/MD5 checksum: 333658 777eb04b75e53b2eeeb83446cc91313c

    ia64 architecture (Intel ia64)

    http://security.debian.org/pool/updates/main/u/unbound/unbound_1.0.2-1+lenny1_ia64.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Mon Jun 8 08:26:26 2026
      from Wales, Uk via Telnet
    • Spearb0y
      Mon Jun 8 06:51:02 2026
      from Massachusetts via SSH
    • Krenn
      Mon Jun 8 05:45:38 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Sun Jun 7 20:58:28 2026
      from Wales, Uk via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (3 / 13)
    Uptime: 28:13:49
    Calls: 12,107
    Calls today: 7
    Files: 15,006
    Messages: 6,518,228

© >>> Magnum BBS <<<, 2026