Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 7: 2021-0036 Critical: bind System Availability Flaw

mageia
Calendar Grey January 17, 2021
Dist Mageia Esm H88
Revised bind modules in Mageia 7 resolve vital concerns impacting system reliability and security.
A flaw was found in bind

Summary

A flaw was found in bind. An assertion failure can occur when trying to verify a truncated response to a TSIG-signed request. The highest threat from this vulnerability is to system availability (CVE-2020-8622).
A flaw was found in bind. Updates to "Update-policy" rules of type "subdomain" are treated as if they were of type "zonesub" which allows updates to all parts of the zone along with the intended subdomain. The highest threat from this vulnerability is to data integrity (CVE-2020-8624).

References

- https://bugs.mageia.org/show_bug.cgi?id=27164

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DQN62GBMCIC5AY4KYADGXNKVY6AJKSJE/

- https://ubuntu.com/security/notices/USN-4468-1

- https://access.redhat.com/errata/RHSA-2020:5011

- https://www.cve.org/CVERecord?id=CVE-2020-8622

- https://www.cve.org/CVERecord?id=CVE-2020-8624

Resolution

SRPMS

- 7/core/bind-9.11.6-1.2.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 17 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0036.html
Type: security
CVE: CVE-2020-8622, CVE-2020-8624

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here