Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Leap 15.2: 2020:1699-1 Moderate: Bind Security Update Details

opensuse
Calendar Grey October 19, 2020
Dist Opensuse Esm H88
A recent Fedora security patch for php addresses 10 vulnerabilities, including 6 critical updates. Update today to protect your web applications!
An update that solves 12 vulnerabilities and has 8 fixes is now available.

Description

This update for bind fixes the following issues:

BIND was upgraded to version 9.16.6:

Note:

- bind is now more strict in regards to DNSSEC. If queries are not

working, check for DNSSEC issues. For instance, if bind is used in a

namserver forwarder chain, the forwarding DNS servers must support

DNSSEC.

Fixing security issues:

- CVE-2020-8616: Further limit the number of queries that can be triggered

from a request. Root and TLD servers are no longer exempt from

max-recursion-queries. Fetches for missing name server. (bsc#1171740)

Address records are limited to 4 for any domain.

- CVE-2020-8617: Replaying a TSIG BADTIME response as a request could

trigger an assertion failure. (bsc#1171740)

- CVE-2019-6477: Fixed an issue where TCP-pipelined queries could bypass

the tcp-clients limit (bsc#1157051).

- CVE-2018-5741: Fixed the documentation (bsc#1109160).

- CVE-2020-8618: It was possible to trigger an INSIST...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1699=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

bind-9.16.6-lp152.14.3.1

bind-chrootenv-9.16.6-lp152.14.3.1

bind-debuginfo-9.16.6-lp152.14.3.1

bind-debugsource-9.16.6-lp152.14.3.1

bind-devel-9.16.6-lp152.14.3.1

bind-utils-9.16.6-lp152.14.3.1

bind-utils-debuginfo-9.16.6-lp152.14.3.1

libbind9-1600-9.16.6-lp152.14.3.1

libbind9-1600-debuginfo-9.16.6-lp152.14.3.1

libdns1605-9.16.6-lp152.14.3.1

libdns1605-debuginfo-9.16.6-lp152.14.3.1

libirs-devel-9.16.6-lp152.14.3.1

libirs1601-9.16.6-lp152.14.3.1

libirs1601-debuginfo-9.16.6-lp152.14.3.1

libisc1606-9.16.6-lp152.14.3.1

libisc1606-debuginfo-9.16.6-lp152.14.3.1

libisccc1600-9.16.6-lp152.14.3.1

libisccc1600-debuginfo-9.16.6-lp152.14.3.1

libisccfg1600-9.16.6-lp152.14.3.1

libisccfg1600-debuginfo-9.16.6-lp152.14.3.1

libns1604-9.16.6-lp152.14.3.1

libns1604-debuginfo-9.16.6-lp152.14.3.1

libuv-debugsource-1.18.0-lp152.4.3.1

libuv-devel-1.18.0-lp152.4.3.1

libuv1-1.18.0-lp152.4.3.1

libuv1-debuginfo-1.18.0-lp152.4.3.1

- openSUSE Leap 15.2 (noarch):

bind-doc-9.16.6-lp152.14.3.1

python3-bind-9.16...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-3136.html

https://www.suse.com/security/cve/CVE-2018-5741.html

https://www.suse.com/security/cve/CVE-2019-6477.html

https://www.suse.com/security/cve/CVE-2020-8616.html

https://www.suse.com/security/cve/CVE-2020-8617.html

https://www.suse.com/security/cve/CVE-2020-8618.html

https://www.suse.com/security/cve/CVE-2020-8619.html

https://www.suse.com/security/cve/CVE-2020-8620.html

https://www.suse.com/security/cve/CVE-2020-8621.html

https://www.suse.com/security/cve/CVE-2020-8622.html

https://www.suse.com/security/cve/CVE-2020-8623.html

https://www.suse.com/security/cve/CVE-2020-8624.html

https://bugzilla.suse.com/1100369

https://bugzilla.suse.com/1109160

https://bugzilla.suse.com/1118367

https://bugzilla.suse.com/1118368

https://bugzilla.suse.com/1128220

https://bugzilla.suse.com/1156205

https://bugzilla.suse.com/1157051

https://bugzilla.suse.com/1161168

https://bugzilla.suse.com/1170667

https://bugzilla.suse.com/1170713

https://bugzilla.suse.com/1171313

https://bugzi...

Read the Full Advisory

Announcement ID: openSUSE-SU-2020:1699-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here