Notification: MySQL 5.5.28, ISC BIND 9.9.2, 9.8.4, 9.7.7, 9.6-ESV-R8

Analysis
Oct 17, 20124 mins

MySQLバージョン5.5.28

プロジェクトホーム:http://www.mysql.com

ライセンス:https://olex.openlogic.com/licenses/49

世界で最もポピュラー なオープンソースデータベースであるMySQLサー バーは、生産性を向上するために、開発や導入、アプリケーションの管理などの多くの機能を企業の開発者、データベース管理者、ISVに与えます。

MySQLサー バーは企業グレードの信頼性とSQL 2003の高い機能を持ったパフォーマンスを合わせ持つ、ビジネス クリティカルなアプリケーションのための最もコスト効率が高いデータベースソリューションです。

MySQLサー バーのデータベースは、高速にそして簡単に使用でき、信頼できる性能を継続的に提供しています。大企業から特殊な組み込みアプリケーションまで1000万以上のプロジェクトがインストールされ、MySQLサーバーは世界中で使用され ています(南極大陸を含む)。

MySQLは サーバーは LAMPスタック (Linux, Apache, MySQL, PHP / Perl / Python) で構築されたアプリケーションの、新しい世代のためのデータベースになりました。20以上のプラットフォーム(Linux, Windows, OS/X, HP-UX, AIX and Netware)で実行できます。そして多くの適応性を与えてくれます。

One of the world’s most popular open source databases, MySQL Server gives corporate developers, DBAs and Independent Software Vendors (ISVs) an array of new enterprise features to increase their productivity whether they are developing, deploying, or managing industrial strength applications.

MySQL Server combines enterprise grade reliability and performance with advanced SQL 2003 features, making it the most cost-effective database solution for your business critical applications.

The MySQL Server database earned its popularity by being fast, easy to use and delivering consistently reliable performance. Installed in more than 10 million projects ranging from large corporations to specialized embedded applications, MySQL Server has a presence on every continent in the world (including Antarctica).

MySQL Server has also become the database of choice for a new generation of applications built on the LAMP stack (Linux, Apache, MySQL, PHP / Perl / Python). Finally, it runs on more than 20 platforms (including Linux, Windows, OS/X, HP-UX, AIX and Netware), giving you a lot of flexibility.

このリリースでの全ての変更についてはこちらのリリースノートをご参照ください:https://dev.mysql.com/doc/refman/5.5/en/news-5-5-28.html

A full description of the changes included in this release can be found in the release notes.


ISC BIND 9.9.2, 9.8.4, 9.7.7, 9.6-ESV-R8

プロジェクトホーム: https://www.isc.org/software/bind

ライセンス: https://olex.openlogic.com/licenses/isc-license

The Berkeley Internet Name Domain (BIND)Unixオペレーティングシステムに対しインターネットネームサーバを実装します。Bindの持つサーバ(deamon)“named”と呼ばれています。そしてリゾルバライブラリです。BINDは、ネットワーク上でのオブジェクトと情報を共有したり、クライアントがリソースやオブジェクトに名前を付けたりすることが可能 な、ネットワークサービスを提供するネームサーバです。

The Berkeley Internet Name Domain (BIND) implements an Internet name server for Unix operating systems. The BIND consists of a server (or `daemon’) called `named’ and a resolver library. A name server is a network service that enables clients to name resources or objects and share this information with other objects in the network.

Bind 9.9.2 セキュリティの修正:

  • 追加部分の応答を書き込んだ場合に、巧妙に細工されたレコードの組み合わせがnamedを停止させる可能性がありました。[CVE-2012-5166] [RT #31090]
  • 65535バイトを超えるRDATAレコードを読み込んだ場合に発生するnamed assert (クラッシュ)の防止。[CVE-2012-4244]  [RT #30416]
  • 初期化前の無効なキャッシュデータを使用することにより検証時に発生するnamedクラッシュ防止。[CVE-2012-3817]  [RT #30025] 
  • named処理の停止等の好ましくない動 作を引き起こす可能性のある長さ0のRDATAに対する不適切な処理が修正さ れました。[CVE-2012-1667]  [RT #29644]
  • ISC_QUEUEの扱いが更新されました。これはまれにUDPクライアントで発生しますが、 安定した速さのTCPクエリを処理するサーバに対する重大な問題になる可能性がありました。[CVE-2012-3868]  [RT #29539 & #30233]

全てのリリースノートは こちらをご参照ください。

  • A deliberately constructed combination of records could cause named to hang while populating the additional section of a response. [CVE-2012-5166] [RT #31090]
  • Prevents a named assert (crash) when queried for a record whose RDATA exceeds 65535 bytes.  [CVE-2012-4244]  [RT #30416]
  • Prevents a named assert (crash) when validating caused by using “Bad cache” data before it has been initialized. [CVE-2012-3817]  [RT #30025] 
  • A condition has been corrected where improper handling of zero-length RDATA could cause undesirable behavior, including termination of the named process. [CVE-2012-1667]  [RT #29644]
  • ISC_QUEUE handling for recursive clients was updated to address a race condition that could cause a memory leak. This rarely occurred with UDP clients, but could be a significant problem for a server handling a steady rate of TCP queries. [CVE-2012-3868]  [RT #29539 & #30233]

Full release notes can be found here.

BIND 9.8.4 セキュリティの修正:

  • 追加部分の応答を書き込んだ場合に、巧妙に細工されたレコードの組み合わせがnamedを停止させる可能性がありました。[CVE-2012-5166] [RT #31090]
  • 65535バイトを超えるRDATAレコードを読み込んだ場合に発生するnamed assert (クラッシュ)の防止。[CVE-2012-4244]  [RT #30416]
  • 初期化前の無効なキャッシュデータを使用することにより検証時に発生するnamedクラッシュ防止。[CVE-2012-3817]  [RT #30025] 
  • named処理の停止等の好ましくない動 作を引き起こす可能性のある長さ0のRDATAに対する不適切な処理が修正さ れました。[CVE-2012-1667]  [RT #29644]

全てのリリースノートは こちらをご参照ください。

  • A deliberately constructed combination of records could cause named to hang while populating the additional section of a response. [CVE-2012-5166] [RT #31090]
  • Prevents a named assert (crash) when queried for a record whose RDATA exceeds 65535 bytes  [CVE-2012-4244]  [RT #30416]
  • Prevents a named assert (crash) when validating caused by using “Bad cache” data before it has been initialized. [CVE-2012-3817]  [RT #30025] 
  • A condition has been corrected where improper handling of zero-length RDATA could cause undesirable behavior, including termination of the named process. [CVE-2012-1667]  [RT #29644]

Full release notes can be found here.

BIND 9.7.7 セキュリティの修正:

  • 追加部分の応答を書き込んだ場合に、巧妙に細工されたレコードの組み合わせがnamedを停止させる可能性がありました。[CVE-2012-5166] [RT #31090]
  • 65535バイトを超えるRDATAレコードを読み込んだ場合に発生するnamed assert (クラッシュ)の防止。[CVE-2012-4244]  [RT #30416]
  • 初期化前の無効なキャッシュデータを使用することにより検証時に発生するnamedクラッシュ防止。[CVE-2012-3817]  [RT #30025] 
  • named処理の停止等の好ましくない動 作を引き起こす可能性のある長さ0のRDATAに対する不適切な処理が修正さ れました。[CVE-2012-1667]  [RT #29644]

全てのリリースノートは こちらをご参照ください。

  • A deliberately constructed combination of records could cause named to hang while populating the additional section of a response. [CVE-2012-5166] [RT #31090]
  • Prevents a named assert (crash) when queried for a record whose RDATA exceeds 65535 bytes  [CVE-2012-4244]  [RT #30416]
  • Prevents a named assert (crash) when validating caused by using “Bad cache” data before it has been initialized. [CVE-2012-3817]  [RT #30025] 
  • A condition has been corrected where improper handling of zero-length RDATA could cause undesirable behavior, including termination of the named process. [CVE-2012-1667]  [RT #29644]

Full release notes can be found here.

BIND 9.6-ESV-R8 セキュリティの修正:

  • 追加部分の応答を書き込んだ場合に、巧妙に細工されたレコードの組み合わせがnamedを停止させる可能性がありました。[CVE-2012-5166] [RT #31090]
  • 65535バイトを超えるRDATAレコードを読み込んだ場合に発生するnamed assert (クラッシュ)の防止。[CVE-2012-4244]  [RT #30416]
  • 初期化前の無効なキャッシュデータを使用することにより検証時に発生するnamedクラッシュ防止。[CVE-2012-3817]  [RT #30025] 
  • named処理の停止等の好ましくない動 作を引き起こす可能性のある長さ0のRDATAに対する不適切な処理が修正さ れました。[CVE-2012-1667]  [RT #29644]

全てのリリースノートは こちらをご参照ください。

  • A deliberately constructed combination of records could cause named to hang while populating the additional section of a response. [CVE-2012-5166] [RT #31090]
  • Prevents a named assert (crash) when queried for a record whose RDATA exceeds 65535 bytes  [CVE-2012-4244]  [RT #30416]
  • Prevents a named assert (crash) when validating caused by using “Bad cache” data before it has been initialized. [CVE-2012-3817]  [RT #30025]
  • A condition has been corrected where improper handling of zero-length RDATA could cause undesirable behavior, including termination of the named process. [CVE-2012-1667] [RT #29644]

Full release notes can be found here.