Oval Definition:oval:com.redhat.rhsa:def:20121139
Revision Date:2012-08-03Version:634
Title:RHSA-2012:1139: bind-dyndb-ldap security update (Important)
Description:The dynamic LDAP back end is a plug-in for BIND that provides back-end capabilities to LDAP databases. It features support for dynamic updates and internal caching that help to reduce the load on LDAP servers.

  • A flaw was found in the way bind-dyndb-ldap performed the escaping of names from DNS requests for use in LDAP queries. A remote attacker able to send DNS queries to a named server that is configured to use bind-dyndb-ldap could use this flaw to cause named to exit unexpectedly with an assertion failure. (CVE-2012-3429)

    Red Hat would like to thank Sigbjorn Lie of Atea Norway for reporting this issue.

    All bind-dyndb-ldap users should upgrade to this updated package, which contains a backported patch to correct this issue. For the update to take effect, the named service must be restarted.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-3429
    CVE-2012-3429
    RHSA-2012:1139
    RHSA-2012:1139-01
    RHSA-2012:1139-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND bind-dyndb-ldap is earlier than 0:1.1.0-0.9.b1.el6_3.1
  • AND bind-dyndb-ldap is signed with Red Hat redhatrelease2 key
  • BACK