Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian 8: DLA-2227-1 Critical: Bind9 Denial Of Service Flaws

debian lts
Calendar Grey May 30, 2020
Dist Debian Esm H88
Uncover essential updates for BIND9 within Debian LTS to maintain optimal functionality and safeguard against vulnerabilities.
Several vulnerabilities were discovered in BIND, a DNS server implementation

Summary

CVE-2020-8616

It was discovered that BIND does not sufficiently limit the number
of fetches performed when processing referrals. An attacker can take
advantage of this flaw to cause a denial of service (performance
degradation) or use the recursing server in a reflection attack with
a high amplification factor.

CVE-2020-8617

It was discovered that a logic error in the code which checks TSIG
validity can be used to trigger an assertion failure, resulting in
denial of service.


For Debian 8 "Jessie", these problems have been fixed in version
1:9.9.5.dfsg-9+deb8u19.

We recommend that you upgrade your bind9 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: bind9
Version: 1:9.9.5.dfsg-9+deb8u19
CVE ID: CVE-2020-8616 CVE-2020-8617

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here