Updated bind packages fix security vulnerabilities Limiting simultaneous TCP clients is ineffective (CVE-2018-5743) Race condition when discarding malformed packets can cause bind to . MGASA-2019-0299 - Updated bind packages fix security vulnerabilities Publication date: 23 Oct 2019 URL: https://advisories.mageia.org/MGASA-2019-0299.html Type: security Affected Mageia releases: 7 CVE: CVE-2018-5743, CVE-2019-6471 Updated bind packages fix security vulnerabilities Limiting simultaneous TCP clients is ineffective (CVE-2018-5743) Race condition when discarding malformed packets can cause bind to exit with assertion failure (CVE-2019-6471) In addition to those two security issues, this package releases also fixes two additional issues: - a missing conflict tag between old bind and bnew ind-utils subpackages, preventing upgrade due to a file conflict - missing root.key file, despite this one being refered in default configuration References: - https://bugs.mageia.org/show_bug.cgi?id=24422 - https://access.redhat.com/errata/RHSA-2019:1294 - https://access.redhat.com/errata/RHSA-2019:1714 - https://www.cve.org/CVERecord?id=CVE-2018-5743 - https://www.cve.org/CVERecord?id=CVE-2019-6471 SRPMS: - 7/core/bind-9.11.6-1.1.mga7 . Improved Bind Modules for Address Vulnerabilities in Mageia 7 and Bolstered Network Consistency with Essential Updates.. bind security update, Mageia network security, TCP client vulnerability, security patch management. . Severity: Critical. LinuxSecurity.com Team
Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-edce28f24b 2017-05-06 17:08:23.402094 --------------------------------------------------------------------------------Name : bind99 Product : Fedora 24 Version : 9.9.9 Release : 4.P8.fc24 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138 --------------------------------------------------------------------------------References: [ 1 ] Bug #1441125 - CVE-2017-3136 bind: Incorrect error handling causes assertion failure when using DNS64 with "break-dnssec yes;" https://bugzilla.redhat.com/show_bug.cgi?id=1441125 [ 2 ] Bug #1441133 - CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver https://bugzilla.redhat.com/show_bug.cgi?id=1441133 [ 3 ] Bug #1441137 - CVE-2017-3138 bind: REQUIRE assertion failure when null command string on control channel is received https://bugzilla.redhat.com/show_bug.cgi?id=1441137 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a354efc764 2017-04-19 16:59:44.108374 --------------------------------------------------------------------------------Name : bind99 Product : Fedora 26 Version : 9.9.9 Release : 5.P8.fc26 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138 --------------------------------------------------------------------------------References: [ 1 ] Bug #1441125 - CVE-2017-3136 bind: Incorrect error handling causes assertion failure when using DNS64 with "break-dnssec yes;" https://bugzilla.redhat.com/show_bug.cgi?id=1441125 [ 2 ] Bug #1441133 - CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver https://bugzilla.redhat.com/show_bug.cgi?id=1441133 [ 3 ] Bug #1441137 - CVE-2017-3138 bind: REQUIRE assertion failure when null command string on control channel is received https://bugzilla.redhat.com/show_bug.cgi?id=1441137 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-f44f2f5a48 2017-01-14 00:22:37.172566 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 25 Version : 9.9.9 Release : 4.P5.fc25 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1411348 - CVE-2016-9131 bind: assertion failure while processing response to an ANY query https://bugzilla.redhat.com/show_bug.cgi?id=1411348 [ 2 ] Bug #1411367 - CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information https://bugzilla.redhat.com/show_bug.cgi?id=1411367 [ 3 ] Bug #1411377 - CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response https://bugzilla.redhat.com/show_bug.cgi?id=1411377 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
security fix. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-09bf9e06ea 2015-12-19 14:50:40.381406 -------------------------------------------------------------------------------- Name : bind-dyndb-ldap Product : Fedora 23 Version : 8.0 Release : 4.fc23 URL : https://pagure.io/bind-dyndb-ldap Summary : LDAP back-end plug-in for BIND Description : This package provides an LDAP back-end plug-in for BIND. It features support for dynamic updates and internal caching, to lift the load off of your LDAP server. -------------------------------------------------------------------------------- Update Information: security fix -------------------------------------------------------------------------------- References: [ 1 ] Bug #1291176 - CVE-2015-8000 bind: responses with a malformed class attribute can trigger an assertion failure in db.c https://bugzilla.redhat.com/show_bug.cgi?id=1291176 [ 2 ] Bug #1291186 - CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c https://bugzilla.redhat.com/show_bug.cgi?id=1291186 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bind-dyndb-ldap' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 809-3
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 809-2
Get the latest Linux and open source security news straight to your inbox.