You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa bind

Sigurnosni nedostaci programskog paketa bind

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2017-04-22 03:35:52.573597

Name : bind
Product : Fedora 24
Version : 9.10.4
Release : 3.P8.fc24
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.

Update Information:

Security fix for CVE-2017-3136, CVE-2017-3137 and CVE-2017-3138

[ 1 ] Bug #1441125 – CVE-2017-3136 bind: Incorrect error handling causes assertion failure when using DNS64 with “break-dnssec yes;”
[ 2 ] Bug #1441133 – CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver
[ 3 ] Bug #1441137 – CVE-2017-3138 bind: REQUIRE assertion failure when null command string on control channel is received

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade bind’ at the command line.
For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list —
To unsubscribe send an email to

AutorDanijel Kozinovic
Cert idNCERT-REF-2017-04-0003-ADV
More in Preporuke
Sigurnosni nedostatak programskog paketa backintime

Otkriven je sigurnosni nedostatak u programskom paketu backintime za operacijski sustav Fedora. Otkriveni nedostatak potencijalnim napadačima omogućuje zaobilaženje sigurnosnih ograničenja....