Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2019:1721-1 Moderate: dnsmasq DNSSEC Security Issue

suse
Calendar Grey July 2, 2019
Dist Suse Esm H88
SUSE has issued a security patch addressing the dnsmasq flaw CVE-2017-15107, categorized with moderate risk, impacting several distributions.
An update that solves one vulnerability and has one errata is now available

Summary

This update for dnsmasq fixes the following issues: Security issue fixed: - CVE-2017-15107: Fixed a vulnerability in DNSSEC implementation. Processing of wildcard synthesized NSEC records may result improper validation for non-existance. (bsc#1076958) Non-security issue fixed: - Reload system dbus to pick up policy change on install (bsc#1054429). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-1721=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2019-1721=1 - SUSE OpenStack Cloud 7:

References

#1054429 #1076958

Cross- CVE-2017-15107

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP4

SUSE Linux Enterprise Desktop 12-SP3

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2017-15107.html

https://bugzilla.suse.com/1054429

https://bugzilla.suse.com/1076958

Announcement ID: SUSE-SU-2019:1721-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here