Advisories ยป MGASA-2016-0030

Updated bind packages fix security vulnerability

Publication date: 20 Jan 2016
Modification date: 20 Jan 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-8704 , CVE-2015-8705

Description

In ISC BIND before 9.10.3-P3, a buffer size check used to guard against
overflow could cause named to exit with an INSIST failure In apl_42.c
(CVE-2015-8704).

In ISC BIND before 9.10.3-P3, errors can occur when OPT pseudo-RR data or
ECS options are formatted to text.  In 9.10.3 through 9.10.3-P2, the issue
may result in a REQUIRE assertion failure in buffer.c, causing a crash.
This can be avoided in named by disabling debug logging (CVE-2015-8705).
                

References

SRPMS

5/core