{"id":"MGASA-2015-0082","summary":"Updated bind packages fix CVE-2015-1349","details":"Updated bind packages fix security vulnerability:\n\nJan-Piet Mens discovered that the BIND DNS server would crash when processing\nan invalid DNSSEC key rollover, either due to an error on the zone operator's\npart, or due to interference with network traffic by an attacker. This issue\naffects configurations with the directives \"dnssec-lookaside auto;\" (as\nenabled in the Mageia default configuration) or \"dnssec-validation auto;\"\n(CVE-2015-1349).\n","modified":"2026-04-16T01:45:52.618036067Z","published":"2015-02-21T18:03:39Z","upstream":["CVE-2015-1349"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0082.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15326"},{"type":"WEB","url":"https://kb.isc.org/article/AA-01235"},{"type":"WEB","url":"https://kb.isc.org/article/AA-01245"},{"type":"WEB","url":"https://www.debian.org/security/2015/dsa-3162"}],"affected":[{"package":{"name":"bind","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/bind?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.9.6.P2-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0082.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}