Update to new ISC supported version 9.9.10.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-167cfa7b09 2017-07-08 16:05:01.877291 --------------------------------------------------------------------------------Name : bind99 Product : Fedora 25 Version : 9.9.10 Release : 1.P2.fc25 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. --------------------------------------------------------------------------------Update Information: Update to new ISC supported version 9.9.10. --------------------------------------------------------------------------------References: [ 1 ] Bug #1466612 - CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1466612 [ 2 ] Bug #1466610 - CVE-2017-3143 bind99: bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1466610 [ 3 ] Bug #1461639 - CVE-2017-3140 bind99: bind: Error processing RPZ rules leads to endless loop while handling query [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1461639 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a354efc764 2017-04-19 16:59:44.108374 --------------------------------------------------------------------------------Name : bind99 Product : Fedora 26 Version : 9.9.9 Release : 5.P8.fc26 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138 --------------------------------------------------------------------------------References: [ 1 ] Bug #1441125 - CVE-2017-3136 bind: Incorrect error handling causes assertion failure when using DNS64 with "break-dnssec yes;" https://bugzilla.redhat.com/show_bug.cgi?id=1441125 [ 2 ] Bug #1441133 - CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver https://bugzilla.redhat.com/show_bug.cgi?id=1441133 [ 3 ] Bug #1441137 - CVE-2017-3138 bind: REQUIRE assertion failure when null command string on control channel is received https://bugzilla.redhat.com/show_bug.cgi?id=1441137 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-3135 (unaffected), fixes regression made by CVE-2016-8864. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-d0c9bf9508 2017-03-05 17:28:15.511263 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 24 Version : 9.9.9 Release : 4.P6.fc24 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-3135 (unaffected), fixes regression made by CVE-2016-8864 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1420193 - CVE-2017-3135 bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash https://bugzilla.redhat.com/show_bug.cgi?id=1420193 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-8f23f564ad 2017-01-16 15:59:40.609058 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 24 Version : 9.9.9 Release : 4.P5.fc24 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1411348 - CVE-2016-9131 bind: assertion failure while processing response to an ANY query https://bugzilla.redhat.com/show_bug.cgi?id=1411348 [ 2 ] Bug #1411367 - CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information https://bugzilla.redhat.com/show_bug.cgi?id=1411367 [ 3 ] Bug #1411377 - CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response https://bugzilla.redhat.com/show_bug.cgi?id=1411377 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-f44f2f5a48 2017-01-14 00:22:37.172566 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 25 Version : 9.9.9 Release : 4.P5.fc25 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1411348 - CVE-2016-9131 bind: assertion failure while processing response to an ANY query https://bugzilla.redhat.com/show_bug.cgi?id=1411348 [ 2 ] Bug #1411367 - CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information https://bugzilla.redhat.com/show_bug.cgi?id=1411367 [ 3 ] Bug #1411377 - CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response https://bugzilla.redhat.com/show_bug.cgi?id=1411377 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2016-6170 ---- Security fix for CVE-2016-8864. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-567a5591e4 2016-11-19 18:59:18.603042 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 25 Version : 9.9.9 Release : 4.P4.fc25 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-6170 ---- Security fix for CVE-2016-8864 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1353563 - CVE-2016-6170 bind: Improper restriction of zone size limit https://bugzilla.redhat.com/show_bug.cgi?id=1353563 [ 2 ] Bug #1389652 - CVE-2016-8864 bind: assertion failure while handling responses containing a DNAME answer https://bugzilla.redhat.com/show_bug.cgi?id=1389652 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest upstream version due to CVE-2016-2776. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-cca77daf70 2016-10-03 13:03:33.169956 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 24 Version : 9.9.9 Release : 2.P3.fc24 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: Update to the latest upstream version due to CVE-2016-2776 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1378380 - CVE-2016-2776 bind: assertion failure in buffer.c while building responses to a specifically constructed request https://bugzilla.redhat.com/show_bug.cgi?id=1378380 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bind99' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New version fixing CVE-2016-1285 CVE-2016-1286. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-161b73fc2c 2016-04-02 00:39:41.509524 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 22 Version : 9.9.8 Release : 4.P4.fc22 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: New version fixing CVE-2016-1285 CVE-2016-1286 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1316446 - CVE-2016-1285 CVE-2016-1286 bind99: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1316446 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bind99' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.