Bug 698286

Summary: BIND 9.8.0: No fix for CVE-2011-1910 in Server/DNS Repository
Product: [openSUSE] openSUSE.org Reporter: Bernhard Schmidt <bernhard.schmidt>
Component: BuildServiceAssignee: Uwe Gansert <ug>
Status: RESOLVED FIXED QA Contact: Adrian Schröter <adrian.schroeter>
Severity: Critical    
Priority: P5 - None CC: meissner
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: SLES 10   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Bernhard Schmidt 2011-06-06 15:52:39 UTC
User-Agent:       Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1

http://www.isc.org/software/bind/advisories/cve-2011-1910 describes a severe remote vulnerability in BIND 9.8, which has been fixed in BIND 9.8.0-P2. This version is not yet available in the server:/dns buildservice repository.

Reproducible: Always

Steps to Reproduce:
1.
2.
3.
Comment 1 Uwe Gansert 2011-06-07 14:16:45 UTC
duplicate

*** This bug has been marked as a duplicate of bug 696585 ***
Comment 2 Uwe Gansert 2011-06-07 14:18:42 UTC
oh, it's about repos. I just read "product SLES10" and so I made it a duplicate.
Comment 3 Uwe Gansert 2011-06-08 08:10:10 UTC
new packages submitted to network/bind
Comment 4 Bernhard Schmidt 2011-06-09 11:56:31 UTC
Unfortunately the build somehow failed for SLES10 and it looks like it isn't even attempting to build for SLES11. Package has not been updated in the repo. Is this expected?
Comment 5 Uwe Gansert 2011-06-09 12:16:55 UTC
SLES11 looks good to me
http://download.opensuse.org/repositories/network/

only SLES10 fails. I hope I'll find the time to look at it soon.
Comment 6 Bernhard Schmidt 2011-06-09 12:18:55 UTC
Right, there is a fixed version in http://download.opensuse.org/repositories/network/, but not in http://download.opensuse.org/repositories/server:/dns/. Has this repository been deprectated?
Comment 7 Uwe Gansert 2011-06-09 14:01:59 UTC
it was decided to switch to network quite some time ago.
To be honest, I don't really know what server:/dns is now. I did not check anything in there since a while but it still has changes.
However, I work on network/bind and network/dnsmasq