Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 481
Alerts This Week
Warning Icon 1 481

SUSE: 2016:0227-1 Critical Update: Resolved Bind DoS Vulnerability

suse
Calendar Grey January 25, 2016
Scroller Suse
SUSE refreshes dns server tools, tackling severe vulnerabilities such as denial of service exploits while bolstering protection protocols.
An update that fixes four vulnerabilities is now available

Summary

This update for bind fixes the following issues: * CVE-2015-8000: Remote denial of service by mis-parsing incoming responses. (bsc#958861) * CVE-2015-5722: DoS against servers performing validation on DNSSEC-signed records. (bsc#944066) * CVE-2015-5477: DoS against authoritative and recursive servers. * CVE-2015-8704: Specific APL data could trigger a crash. (bsc#962189) Security Issues: * CVE-2015-8000 * CVE-2015-5722 * CVE-2015-5477 * CVE-2015-8704 Package List:

References

#939567 #944066 #958861 #962189

Cross- CVE-2015-5477 CVE-2015-5722 CVE-2015-8000

CVE-2015-8704

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

https://www.suse.com/security/cve/CVE-2015-5477.html

https://www.suse.com/security/cve/CVE-2015-5722.html

https://www.suse.com/security/cve/CVE-2015-8000.html

https://www.suse.com/security/cve/CVE-2015-8704.html

https://bugzilla.suse.com/show_bug.cgi?id=939567

https://bugzilla.suse.com/show_bug.cgi?id=944066

https://bugzilla.suse.com/show_bug.cgi?id=958861

https://bugzilla.suse.com/show_bug.cgi?id=962189

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0227-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.