Advisories ยป MGASA-2020-0259

Updated bind packages fix security vulnerability

Publication date: 15 Jun 2020
Modification date: 15 Jun 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-6477 , CVE-2020-8616 , CVE-2020-8617

Description

Updated bind packages fix security vulnerabilities:

It was discovered that Bind incorrectly handled certain TCP-pipelined
queries.
A remote attacker could possibly use this issue to cause Bind to consume
resources, resulting in a denial of service (CVE-2019-6477).

Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Bind
incorrectly limited certain fetches. A remote attacker could possibly
use this issue to cause Bind to consume resources, leading to a denial
of service, or possibly use Bind to perform a reflection attack
(CVE-2020-8616).

Tobias Klein discovered that Bind incorrectly handled checking TSIG
validity.
A remote attacker could use this issue to cause Bind to crash, resulting
in a denial of service, or possibly perform other attacks 
(CVE-2020-8617).
                

References

SRPMS

7/core