Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Fedora 25: 2017-167cfa7b09 Critical: Bind99 TSIG Authentication Flaws

fedora
Calendar Grey July 8, 2017
Dist Fedora Esm H88
Boost your framework by applying the latest security patch from Fedora for bind99. Update to version 9.9.10 to enhance DNS reliability.
Update to new ISC supported version 9.9.10.

Summary

BIND (Berkeley Internet Name Domain) is an implementation of the DNS

(Domain Name System) protocols. This package set contains only export

version of BIND libraries, that are used for building ISC DHCP.

Update to new ISC supported version 9.9.10.

[ 1 ] Bug #1466612 - CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1466612

[ 2 ] Bug #1466610 - CVE-2017-3143 bind99: bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1466610

[ 3 ] Bug #1461639 - CVE-2017-3140 bind99: bind: Error processing RPZ rules leads to endless loop while handling query [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1461639

su -c 'dnf upgrade bind99' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 25
Version: 9.9.10
Release: 1.P2.fc25
URL: Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here