| « Emergency trip to India | puppet fact for CentOS Version » |
CentOS and reissue of updated packages for CVE-2008-1447
Some people will notice that a second set ( i386 x86_64 ) of announcements were just made to address the issue raised in CVE-2008-1447 after the initial announcement ( i386 x86_64 ).
These are indeed newer packages based on bind-9.3.4-6.0.2.P1.el5_2 ( the original update was based on bind-9.3.4-6.0.1.P1.el5_2 ). Reason for this reissue from upstream is explained at : https://bugzilla.redhat.com/show_bug.cgi?id=454852 and I highly recommend you look at it. Specially if you run ipv6 on the wire.
Of-course it would have been nicer if upstream had issued another RHSA rather than just update the existing one with newer packages. I wonder if there were operational issues or release process issues to blame for this.
- KB