#11704: bind9 bind 9.12.3-P4 (CVE-2018-5744 CVE-2018-5745 CVE-2019-6465)
-------------------------+------------------------
Reporter: bdubbs | Owner: blfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 8.5
Component: BOOK | Version: SVN
Severity: normal | Resolution:
Keywords: |
-------------------------+------------------------
Changes (by renodr):
* priority: normal => high
Comment:
{{{
Today ISC disclosed three vulnerabilities affecting multiple versions of
BIND. Full details on versions affected and more information about the
vulnerabilities are available via these articles in the ISC Knowledge
Base:
CVE-2018-5744:
A specially crafted packet can cause named to leak memory
https://kb.isc.org/docs/cve-2018-5744
CVE-2018-5745:
An assertion failure can occur if a trust anchor rolls over to
an unsupported key algorithm when a server is using managed-keys
https://kb.isc.org/docs/cve-2018-5745
CVE-2019-6465:
Controls for zone transfers may not be properly applied to
Dynamically Loadable Zones (DLZs) if the zones are writable.
https://kb.isc.org/docs/cve-2019-6465
New software versions are available from the ISC downloads page:
https://www.isc.org/downloads
With the public disclosure of these vulnerabilities, parties which
had been given advance notice concerning them are released from
non-disclosure and packagers and redistributors are encouraged to
publish updated packages containing fixes.
If you have additional questions, please direct them to
[email protected]
Thank you,
Michael McNally
ISC Security Officer
}}}
--
Ticket URL: <http://wiki.linuxfromscratch.org/blfs/ticket/11704#comment:1>
BLFS Trac <http://wiki.linuxfromscratch.org/blfs>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page