Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE 2017 0999 1 Critical: Bind Denial Of Service Vulnerability Alert

suse
Calendar Grey April 13, 2017
Dist Suse Esm H88
Canonical releases patch for OpenSSL addressing 4 vulnerabilities, bolstering security for all users. Step-by-step guide provided.
An update that fixes 5 vulnerabilities is now available

Summary

This update for bind fixes the following issues: CVE-2017-3137 (bsc#1033467): Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could have been exploited to cause a denial of service of a bind server performing recursion. CVE-2017-3136 (bsc#1033466): An attacker could have constructed a query that would cause a denial of service of servers configured to use DNS64. CVE-2017-3138 (bsc#1033468): An attacker with access to the BIND control channel could have caused the server to stop by triggering an assertion failure. CVE-2016-6170 (bsc#987866): Primary DNS servers could have caused a denial of service of secondary DNS servers via a large AXFR response. IXFR servers could have caused a denial of service of IXFR clients via a large

References

#1033466 #1033467 #1033468 #987866 #989528

Cross- CVE-2016-2775 CVE-2016-6170 CVE-2017-3136

CVE-2017-3137 CVE-2017-3138

Affected Products:

SUSE Linux Enterprise Server for SAP 12

SUSE Linux Enterprise Server 12-LTSS

https://www.suse.com/security/cve/CVE-2016-2775.html

https://www.suse.com/security/cve/CVE-2016-6170.html

https://www.suse.com/security/cve/CVE-2017-3136.html

https://www.suse.com/security/cve/CVE-2017-3137.html

https://www.suse.com/security/cve/CVE-2017-3138.html

https://bugzilla.suse.com/1033466

https://bugzilla.suse.com/1033467

https://bugzilla.suse.com/1033468

https://bugzilla.suse.com/987866

https://bugzilla.suse.com/989528

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:0999-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here