You are here
Home > Preporuke > Ranjivosti programskog paketa bind

Ranjivosti programskog paketa bind

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-14958
2015-09-24 05:07:02.608162
——————————————————————————–

Name : bind99
Product : Fedora 22
Version : 9.9.7
Release : 7.P3.fc22
URL : http://www.isc.org/products/BIND/
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. This package set contains only export
version of BIND libraries, that are used for building ISC DHCP.

——————————————————————————–
Update Information:

Fixed https://bugzilla.redhat.com/show_bug.cgi?id=1259563
https://bugzilla.redhat.com/show_bug.cgi?id=1259691
——————————————————————————–
References:

[ 1 ] Bug #1259085 – CVE-2015-5986 Bind: fromwire_openpgpkey() incorrect boundary check Denial of Service
https://bugzilla.redhat.com/show_bug.cgi?id=1259085
[ 2 ] Bug #1259087 – CVE-2015-5722 bind: malformed DNSSEC key failed assertion denial of service
https://bugzilla.redhat.com/show_bug.cgi?id=1259087
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update bind99’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorTomislav Protega
Cert idNCERT-REF-2015-09-0017-ADV
CveCVE-2015-5986 CVE-2015-5722
ID izvornikaFEDORA-2015-14958
Proizvodbind99
Izvorhttp://www.redhat.com
Top
More in Preporuke
Ranjivost programskog paketa groovy

Otkrivena je ranjivost u klasi MethodClosure (runtime/MethodClosure.java) unutar programskog paketa groovy za Fedoru. Ranjivost potencijalnim udaljenim napadačima može omogućiti izvršavanje...

Close