Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE 15.1: 2020:1701-1 Moderate Update: bind Security Issues

opensuse
Calendar Grey October 20, 2020
Dist Opensuse Esm H88
This Ubuntu security patch resolves various vulnerabilities in apache, improving its efficiency and protective features.
An update that solves 12 vulnerabilities and has 8 fixes is now available.

Description

This update for bind fixes the following issues:

BIND was upgraded to version 9.16.6:

Note:

- bind is now more strict in regards to DNSSEC. If queries are not

working, check for DNSSEC issues. For instance, if bind is used in a

namserver forwarder chain, the forwarding DNS servers must support

DNSSEC.

Fixing security issues:

- CVE-2020-8616: Further limit the number of queries that can be triggered

from a request. Root and TLD servers are no longer exempt from

max-recursion-queries. Fetches for missing name server. (bsc#1171740)

Address records are limited to 4 for any domain.

- CVE-2020-8617: Replaying a TSIG BADTIME response as a request could

trigger an assertion failure. (bsc#1171740)

- CVE-2019-6477: Fixed an issue where TCP-pipelined queries could bypass

the tcp-clients limit (bsc#1157051).

- CVE-2018-5741: Fixed the documentation (bsc#1109160).

- CVE-2020-8618: It was possible to trigger an INSIST...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-1701=1

Package List

- openSUSE Leap 15.1 (i586 x86_64):

bind-9.16.6-lp151.11.9.1

bind-chrootenv-9.16.6-lp151.11.9.1

bind-debuginfo-9.16.6-lp151.11.9.1

bind-debugsource-9.16.6-lp151.11.9.1

bind-devel-9.16.6-lp151.11.9.1

bind-utils-9.16.6-lp151.11.9.1

bind-utils-debuginfo-9.16.6-lp151.11.9.1

libbind9-1600-9.16.6-lp151.11.9.1

libbind9-1600-debuginfo-9.16.6-lp151.11.9.1

libdns1605-9.16.6-lp151.11.9.1

libdns1605-debuginfo-9.16.6-lp151.11.9.1

libirs-devel-9.16.6-lp151.11.9.1

libirs1601-9.16.6-lp151.11.9.1

libirs1601-debuginfo-9.16.6-lp151.11.9.1

libisc1606-9.16.6-lp151.11.9.1

libisc1606-debuginfo-9.16.6-lp151.11.9.1

libisccc1600-9.16.6-lp151.11.9.1

libisccc1600-debuginfo-9.16.6-lp151.11.9.1

libisccfg1600-9.16.6-lp151.11.9.1

libisccfg1600-debuginfo-9.16.6-lp151.11.9.1

libns1604-9.16.6-lp151.11.9.1

libns1604-debuginfo-9.16.6-lp151.11.9.1

libuv-debugsource-1.18.0-lp151.3.3.1

libuv-devel-1.18.0-lp151.3.3.1

libuv1-1.18.0-lp151.3.3.1

libuv1-debuginfo-1.18.0-lp151.3.3.1

- openSUSE Leap 15.1 (x86_64):

bind-devel-32bit-9.16.6-lp151.11.9.1

libbind9-...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-3136.html

https://www.suse.com/security/cve/CVE-2018-5741.html

https://www.suse.com/security/cve/CVE-2019-6477.html

https://www.suse.com/security/cve/CVE-2020-8616.html

https://www.suse.com/security/cve/CVE-2020-8617.html

https://www.suse.com/security/cve/CVE-2020-8618.html

https://www.suse.com/security/cve/CVE-2020-8619.html

https://www.suse.com/security/cve/CVE-2020-8620.html

https://www.suse.com/security/cve/CVE-2020-8621.html

https://www.suse.com/security/cve/CVE-2020-8622.html

https://www.suse.com/security/cve/CVE-2020-8623.html

https://www.suse.com/security/cve/CVE-2020-8624.html

https://bugzilla.suse.com/1100369

https://bugzilla.suse.com/1109160

https://bugzilla.suse.com/1118367

https://bugzilla.suse.com/1118368

https://bugzilla.suse.com/1128220

https://bugzilla.suse.com/1156205

https://bugzilla.suse.com/1157051

https://bugzilla.suse.com/1161168

https://bugzilla.suse.com/1170667

https://bugzilla.suse.com/1170713

https://bugzilla.suse.com/1171313

https://bugzi...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1701-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here