Synopsis:          Important: bind97 security update
Advisory ID:       SLSA-2014:1985-1
Issue Date:        2014-12-12
CVE Numbers:       CVE-2014-8500
--

A denial of service flaw was found in the way BIND followed DNS
delegations. A remote attacker could use a specially crafted zone
containing a large number of referrals which, when looked up and
processed, would cause named to use excessive amounts of memory or crash.
(CVE-2014-8500)

After installing the update, the BIND daemon (named) will be restarted
automatically.
--

SL5
  x86_64
    bind97-9.7.0-21.P2.el5_11.1.x86_64.rpm
    bind97-chroot-9.7.0-21.P2.el5_11.1.x86_64.rpm
    bind97-debuginfo-9.7.0-21.P2.el5_11.1.i386.rpm
    bind97-debuginfo-9.7.0-21.P2.el5_11.1.x86_64.rpm
    bind97-devel-9.7.0-21.P2.el5_11.1.i386.rpm
    bind97-devel-9.7.0-21.P2.el5_11.1.x86_64.rpm
    bind97-libs-9.7.0-21.P2.el5_11.1.i386.rpm
    bind97-libs-9.7.0-21.P2.el5_11.1.x86_64.rpm
    bind97-utils-9.7.0-21.P2.el5_11.1.x86_64.rpm
  i386
    bind97-9.7.0-21.P2.el5_11.1.i386.rpm
    bind97-chroot-9.7.0-21.P2.el5_11.1.i386.rpm
    bind97-debuginfo-9.7.0-21.P2.el5_11.1.i386.rpm
    bind97-devel-9.7.0-21.P2.el5_11.1.i386.rpm
    bind97-libs-9.7.0-21.P2.el5_11.1.i386.rpm
    bind97-utils-9.7.0-21.P2.el5_11.1.i386.rpm

- Scientific Linux Development Team