Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
- Update to 4.6.2 Release notes: https://doc.powerdns.com/authoritative/changelog/4.6.html#change-4.6.2 ---- - Update to 4.6.1 Release notes: https://doc.powerdns.com/authoritative/changelog/4.6.html#change-4.6.1. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8367cefdea 2022-04-20 19:09:32.222133 --------------------------------------------------------------------------------Name : pdns Product : Fedora 35 Version : 4.6.2 Release : 1.fc35 URL : https://www.powerdns.com/ Summary : A modern, advanced and high performance authoritative-only nameserver Description : The PowerDNS Nameserver is a modern, advanced and high performance authoritative-only nameserver. It is written from scratch and conforms to all relevant DNS standards documents. Furthermore, PowerDNS interfaces with almost any database. --------------------------------------------------------------------------------Update Information: - Update to 4.6.2 Release notes: https://doc.powerdns.com/authoritative/changelog/4.6.html#change-4.6.2 ---- -Update to 4.6.1 Release notes: https://doc.powerdns.com/authoritative/changelog/4.6.html#change-4.6.1 --------------------------------------------------------------------------------ChangeLog: * Tue Apr 12 2022 Morten Stevens - 4.6.2-1 - Update to 4.6.2 * Sun Apr 10 2022 Morten Stevens - 4.6.1-1 - Update to 4.6.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #2069400 - CVE-2022-27227 pdns: pdns,pdns-recursor: Incomplete zone transfers handled as successful [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2069400 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8367cefdea' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for bind ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1533-1 Rating: important References: #1104129 #1126068 #1126069 #1133185 Cross-References: CVE-2018-5740 CVE-2018-5743 CVE-2018-5745 CVE-2019-6465 Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for bind fixes the following issues: Security issues fixed: - CVE-2019-6465: Fixed an issue where controls for zone transfers may not be properly applied to Dynamically Loadable Zones (bsc#1126069). - CVE-2018-5745: Fixed a denial of service vulnerability if a trust anchor rolls over to an unsupported key algorithm when using managed-keys (bsc#1126068). - CVE-2018-5743: Fixed a denial of service vulnerability which could be caused by to many simultaneous TCP connections (bsc#1133185). - CVE-2018-5740: Fixed a denial of service vulnerability in the "deny-answer-aliases" feature (bsc#1104129). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1533=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1533=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): bind-9.11.2-lp151.11.3.1 bind-chrootenv-9.11.2-lp151.11.3.1 bind-debuginfo-9.11.2-lp151.11.3.1 bind-debugsource-9.11.2-lp151.11.3.1 bind-devel-9.11.2-lp151.11.3.1 bind-lwresd-9.11.2-lp151.11.3.1 bind-lwresd-debuginfo-9.11.2-lp151.11.3.1 bind-utils-9.11.2-lp151.11.3.1 bind-utils-debuginfo-9.11.2-lp151.11.3.1 libbind9-160-9.11.2-lp151.11.3.1 libbind9-160-debuginfo-9.11.2-lp151.11.3.1 libdns169-9.11.2-lp151.11.3.1 libdns169-debuginfo-9.11.2-lp151.11.3.1 libirs-devel-9.11.2-lp151.11.3.1 libirs160-9.11.2-lp151.11.3.1 libirs160-debuginfo-9.11.2-lp151.11.3.1 libisc166-9.11.2-lp151.11.3.1 libisc166-debuginfo-9.11.2-lp151.11.3.1 libisccc160-9.11.2-lp151.11.3.1 libisccc160-debuginfo-9.11.2-lp151.11.3.1 libisccfg160-9.11.2-lp151.11.3.1 libisccfg160-debuginfo-9.11.2-lp151.11.3.1 liblwres160-9.11.2-lp151.11.3.1 liblwres160-debuginfo-9.11.2-lp151.11.3.1 - openSUSE Leap 15.1 (x86_64): bind-devel-32bit-9.11.2-lp151.11.3.1 libbind9-160-32bit-9.11.2-lp151.11.3.1 libbind9-160-32bit-debuginfo-9.11.2-lp151.11.3.1 libdns169-32bit-9.11.2-lp151.11.3.1 libdns169-32bit-debuginfo-9.11.2-lp151.11.3.1 libirs160-32bit-9.11.2-lp151.11.3.1 libirs160-32bit-debuginfo-9.11.2-lp151.11.3.1 libisc166-32bit-9.11.2-lp151.11.3.1 libisc166-32bit-debuginfo-9.11.2-lp151.11.3.1 libisccc160-32bit-9.11.2-lp151.11.3.1 libisccc160-32bit-debuginfo-9.11.2-lp151.11.3.1 libisccfg160-32bit-9.11.2-lp151.11.3.1 libisccfg160-32bit-debuginfo-9.11.2-lp151.11.3.1 liblwres160-32bit-9.11.2-lp151.11.3.1 liblwres160-32bit-debuginfo-9.11.2-lp151.11.3.1 - openSUSE Leap 15.1 (noarch): bind-doc-9.11.2-lp151.11.3.1 python3-bind-9.11.2-lp151.11.3.1 - openSUSE Leap 15.0 (i586 x86_64): bind-9.11.2-lp150.8.13.1 bind-chrootenv-9.11.2-lp150.8.13.1 bind-debuginfo-9.11.2-lp150.8.13.1 bind-debugsource-9.11.2-lp150.8.13.1 bind-devel-9.11.2-lp150.8.13.1 bind-lwresd-9.11.2-lp150.8.13.1 bind-lwresd-debuginfo-9.11.2-lp150.8.13.1 bind-utils-9.11.2-lp150.8.13.1 bind-utils-debuginfo-9.11.2-lp150.8.13.1 libbind9-160-9.11.2-lp150.8.13.1 libbind9-160-debuginfo-9.11.2-lp150.8.13.1 libdns169-9.11.2-lp150.8.13.1 libdns169-debuginfo-9.11.2-lp150.8.13.1 libirs-devel-9.11.2-lp150.8.13.1 libirs160-9.11.2-lp150.8.13.1 libirs160-debuginfo-9.11.2-lp150.8.13.1 libisc166-9.11.2-lp150.8.13.1 libisc166-debuginfo-9.11.2-lp150.8.13.1 libisccc160-9.11.2-lp150.8.13.1 libisccc160-debuginfo-9.11.2-lp150.8.13.1 libisccfg160-9.11.2-lp150.8.13.1 libisccfg160-debuginfo-9.11.2-lp150.8.13.1 liblwres160-9.11.2-lp150.8.13.1 liblwres160-debuginfo-9.11.2-lp150.8.13.1 - openSUSE Leap 15.0 (noarch): bind-doc-9.11.2-lp150.8.13.1 python3-bind-9.11.2-lp150.8.13.1 - openSUSE Leap 15.0 (x86_64): bind-devel-32bit-9.11.2-lp150.8.13.1 libbind9-160-32bit-9.11.2-lp150.8.13.1 libbind9-160-32bit-debuginfo-9.11.2-lp150.8.13.1 libdns169-32bit-9.11.2-lp150.8.13.1 libdns169-32bit-debuginfo-9.11.2-lp150.8.13.1 libirs160-32bit-9.11.2-lp150.8.13.1 libirs160-32bit-debuginfo-9.11.2-lp150.8.13.1 libisc166-32bit-9.11.2-lp150.8.13.1 libisc166-32bit-debuginfo-9.11.2-lp150.8.13.1 libisccc160-32bit-9.11.2-lp150.8.13.1 libisccc160-32bit-debuginfo-9.11.2-lp150.8.13.1 libisccfg160-32bit-9.11.2-lp150.8.13.1 libisccfg160-32bit-debuginfo-9.11.2-lp150.8.13.1 liblwres160-32bit-9.11.2-lp150.8.13.1 liblwres160-32bit-debuginfo-9.11.2-lp150.8.13.1 References: https://www.suse.com/security/cve/CVE-2018-5740.html https://www.suse.com/security/cve/CVE-2018-5743.html https://www.suse.com/security/cve/CVE-2018-5745.html https://www.suse.com/security/cve/CVE-2019-6465.html https://bugzilla.suse.com/1104129 https://bugzilla.suse.com/1126068 https://bugzilla.suse.com/1126069 https://bugzilla.suse.com/1133185 -- . Crucial openSUSE security patch for bind addresses multiple significant vulnerabilities. Discover thespecifics of the issues and resolutions available now.. openSUSE Security, bind update, denial of service, security fix, system vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Two issues have been found in bind9, the Internet Domain Name Server. CVE-2019-6465 . Package : bind9 Version : 1:9.9.5.dfsg-9+deb8u17 CVE ID : CVE-2018-5745 CVE-2019-6465 Two issues have been found in bind9, the Internet Domain Name Server. CVE-2019-6465 Zone transfer for DLZs are executed though not permitted by ACLs. CVE-2018-5745 Avoid assertion and thus causing named to deliberately exit when a trust anchor's key is replaced with a key which uses an unsupported algorithm. For Debian 8 "Jessie", these problems have been fixed in version 1:9.9.5.dfsg-9+deb8u17. We recommend that you upgrade your bind9 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : bind9 Version : 1:9.9.5.dfsg-9+deb8u17 CVE ID : CVE-2018-5745 CVE-2019-6465 Two issues hav. bind9, found, internet, domain, server, cve-2019-6465, package. . Severity: Critical. LinuxSecurity.com Team
Bind could be made to serve incorrect information or expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-3346-3 November 08, 2017 bind9 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Bind could be made to serve incorrect information or expose sensitive information over the network. Software Description: - bind9: Internet Domain Name Server Details: USN-3346-1 and USN-3346-2 fixed two vulnerabilities in Bind and a regression, respectively. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Clément Berthaux discovered that Bind did not correctly check TSIG authentication for zone update requests. An attacker could use this to improperly perform zone updates. (CVE-2017-3143) Clément Berthaux discovered that Bind did not correctly check TSIG authentication for zone transfer requests. An attacker could use this to improperly transfer entire zones. (CVE-2017-3142) In addition, this update adds the new root zone key signing key (KSK). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: bind9 1:9.8.1.dfsg.P1-4ubuntu0.23 After a standard system update you need to restart Bind to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3346-1 CVE-2017-3142, CVE-2017-3143 . Exploitable flaws in Ubuntu systems can result in data breaches or misrouted information. It is recommended to apply updates.. Bind9 Threats, Ubuntu Security Update, Zone Transfer Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-001f135337 2017-07-11 18:56:33.196447 --------------------------------------------------------------------------------Name : bind-dyndb-ldap Product : Fedora 24 Version : 10.1 Release : 2.fc24 URL : https://pagure.io/bind-dyndb-ldap Summary : LDAP back-end plug-in for BIND Description : This package provides an LDAP back-end plug-in for BIND. It features support for dynamic updates and internal caching, to lift the load off of your LDAP server. --------------------------------------------------------------------------------Update Information: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 --------------------------------------------------------------------------------References: [ 1 ] Bug #1466193 - CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates https://bugzilla.redhat.com/show_bug.cgi?id=1466193 [ 2 ] Bug #1461302 - CVE-2017-3140 bind: Error processing RPZ rules leads to endless loop while handling query https://bugzilla.redhat.com/show_bug.cgi?id=1461302 [ 3 ] Bug #1466189 - CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers https://bugzilla.redhat.com/show_bug.cgi?id=1466189 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind-dyndb-ldap' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to last supported version, fixes CVE-2017-3142 and CVE-2017-3143. Includes minor fix of missing dependencies.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-30f678e62a 2017-07-07 22:40:59.830090 --------------------------------------------------------------------------------Name : bind Product : Fedora 26 Version : 9.11.1 Release : 2.P2.fc26 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. --------------------------------------------------------------------------------Update Information: Update to last supported version, fixes CVE-2017-3142 and CVE-2017-3143. Includes minor fix of missing dependencies. --------------------------------------------------------------------------------References: [ 1 ] Bug #1466189 - CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers https://bugzilla.redhat.com/show_bug.cgi?id=1466189 [ 2 ] Bug #1466193 - CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates https://bugzilla.redhat.com/show_bug.cgi?id=1466193 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Bind could be made to serve incorrect information or expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-3346-1 June 29, 2017 bind9 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Bind could be made to serve incorrect information or expose sensitive information over the network. Software Description: - bind9: Internet Domain Name Server Details: Clément Berthaux discovered that Bind did not correctly check TSIG authentication for zone update requests. An attacker could use this to improperly perform zone updates. (CVE-2017-3143) Clément Berthaux discovered that Bind did not correctly check TSIG authentication for zone transfer requests. An attacker could use this to improperly transfer entire zones. (CVE-2017-3142) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: bind9 1:9.10.3.dfsg.P4-10.1ubuntu5.1 Ubuntu 16.10: bind9 1:9.10.3.dfsg.P4-10.1ubuntu1.7 Ubuntu 16.04 LTS: bind9 1:9.10.3.dfsg.P4-8ubuntu1.7 Ubuntu 14.04 LTS: bind9 1:9.9.5.dfsg-3ubuntu0.15 After a standard system update you need to restart Bind to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3346-1 CVE-2017-3142, CVE-2017-3143 Package Information: https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-10.1ubuntu5.1 https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-10.1ubuntu1.7 https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.7 https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.15 . Urgent update for Ubuntuusers regarding Bind9 security vulnerabilities that may expose sensitive data. Apply the recommended updates to protect your system. bind9 Updates, Ubuntu Security Notices, Network Risks. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.