RHSA-2008:0533: Important: bind security update

Published Jul 8, 2008
·
Updated

ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS(Domain Name System) protocols.The DNS protocol protects against spoofing attacks by requiring an attackerto predict both the DNS transaction ID and UDP source port of a request. Inrecent years, a number of papers have found problems with DNSimplementations which make it easier for an attacker to perform DNScache-poisoning attacks.Previous versions of BIND did not use randomized UDP source ports. If anattacker was able to predict the random DNS transaction ID, this could makeDNS cache-poisoning attacks easier. In order to provide more resilience,BIND has been updated to use a range of random UDP source ports.(CVE-2008-1447)Note: This errata also updates SELinux policy on Red Hat Enterprise Linux 4and 5 to allow BIND to use random UDP source ports.Users of BIND are advised to upgrade to these updated packages, whichcontain a backported patch to add this functionality.Red Hat would like to thank Dan Kaminsky for reporting this issue.

Affected Software

49 affected componentsFixes available
redhat/bind<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-chroot<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-chroot<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-devel<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-devel<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-devel<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-devel<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-libbind-devel<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-libbind-devel<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-libbind-devel<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-libbind-devel<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-libs<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-libs<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-libs<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-libs<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-sdb<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-sdb<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-utils<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-utils<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/caching-nameserver<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/caching-nameserver<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/selinux-policy<2.4.6-137.1.el5_2
2.4.6-137.1.el5_2
redhat/selinux-policy-devel<2.4.6-137.1.el5_2
2.4.6-137.1.el5_2
redhat/selinux-policy-mls<2.4.6-137.1.el5_2
2.4.6-137.1.el5_2
redhat/selinux-policy-strict<2.4.6-137.1.el5_2
2.4.6-137.1.el5_2
redhat/selinux-policy-targeted<2.4.6-137.1.el5_2
2.4.6-137.1.el5_2
redhat/bind<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-chroot<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-chroot<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-sdb<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-sdb<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind-utils<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/bind-utils<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/caching-nameserver<9.3.4-6.0.1.P1.el5_2
9.3.4-6.0.1.P1.el5_2
redhat/caching-nameserver<9.3.4-6.0.2.P1.el5_2
9.3.4-6.0.2.P1.el5_2
redhat/bind<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/bind-chroot<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/bind-devel<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/bind-libs<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/bind-libs<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/bind-utils<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/selinux-policy-targeted<1.17.30-2.150.el4
1.17.30-2.150.el4
redhat/selinux-policy-targeted-sources<1.17.30-2.150.el4
1.17.30-2.150.el4
redhat/bind<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/bind-chroot<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/bind-devel<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4
redhat/bind-utils<9.2.4-28.0.1.el4
9.2.4-28.0.1.el4

Remediation

Event History

Jul 8, 2008
Advisory Published
via Red Hat·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2008:0533?

The severity of RHSA-2008:0533 is categorized as important.

2

How do I fix RHSA-2008:0533?

To fix RHSA-2008:0533, update to the recommended versions of the affected BIND packages, specifically 9.3.4-6.0.1.P1.el5_2 or 9.3.4-6.0.2.P1.el5_2.

3

What are the affected software versions for RHSA-2008:0533?

Affected software versions include BIND 9.3.4-6.0.1.P1.el5_2 and BIND 9.3.4-6.0.2.P1.el5_2 among others.

4

What types of attacks does RHSA-2008:0533 protect against?

RHSA-2008:0533 addresses vulnerabilities in BIND that could be exploited via DNS spoofing attacks.

5

Which packages are vulnerable in RHSA-2008:0533?

Vulnerable packages include bind, bind-devel, bind-libs, and others specific to versions mentioned in RHSA-2008:0533.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203