A use-after-free flaw leading to denial of service was found in the way BIND internally handled cleanup operations on upstream recursion fetch contexts. A remote attacker could potentially use this flaw to make named, acting as a DNSSEC validating resolver, exit unexpectedly with an assertion failure via a specially crafted DNS request. (CVE-2017-3145) SL6 x86_64 bind-debuginfo-9.8.2-0. [More...]. Synopsis: Important: bind security update Advisory ID: SLSA-2018:0101-1 Issue Date: 2018-01-22 CVE Numbers: CVE-2017-3145 -- Security Fix(es): * A use-after-free flaw leading to denial of service was found in the way BIND internally handled cleanup operations on upstream recursion fetch contexts. A remote attacker could potentially use this flaw to make named, acting as a DNSSEC validating resolver, exit unexpectedly with an assertion failure via a specially crafted DNS request. (CVE-2017-3145) -- SL6 x86_64 bind-debuginfo-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-debuginfo-9.8.2-0.62.rc1.el6_9.5.x86_64.rpm bind-libs-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-libs-9.8.2-0.62.rc1.el6_9.5.x86_64.rpm bind-utils-9.8.2-0.62.rc1.el6_9.5.x86_64.rpm bind-9.8.2-0.62.rc1.el6_9.5.x86_64.rpm bind-chroot-9.8.2-0.62.rc1.el6_9.5.x86_64.rpm bind-devel-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-devel-9.8.2-0.62.rc1.el6_9.5.x86_64.rpm bind-sdb-9.8.2-0.62.rc1.el6_9.5.x86_64.rpm i386 bind-debuginfo-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-libs-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-utils-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-chroot-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-devel-9.8.2-0.62.rc1.el6_9.5.i686.rpm bind-sdb-9.8.2-0.62.rc1.el6_9.5.i686.rpm - Scientific Linux Development Team . Crucial patch released for SL6.x targeting a critical buffer overflow vulnerability that may result in service interruption.. bind security update, use-after-free flaw, denial of service, SL6 security, BIND cleanup fix. . Severity:Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.