BIND: Denial of service — GLSA 201401-34

Multiple vulnerabilities have been found in BIND, possibly resulting in Denial of Service.

Affected packages

net-dns/bind on all architectures
Affected versions < 9.9.4_p2
Unaffected versions >= 9.9.4_p2

Background

BIND is the Berkeley Internet Name Domain Server.

Description

Multiple vulnerabilities have been discovered in BIND. Please review the CVE identifiers referenced below for details.

Impact

A remote attacker may be able to cause a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All BIND users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-dns/bind-9.9.4_p2"
 

References

Release date
January 29, 2014

Latest revision
January 29, 2014: 1

Severity
normal

Exploitable
remote

Bugzilla entries