You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa bind

Sigurnosni nedostaci programskog paketa bind

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2017-07-11 18:56:33.196447

Name : bind
Product : Fedora 24
Version : 9.10.5
Release : 2.P2.fc24
Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server
Description :
BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.

Update Information:

Update back to ISC supported version. Security fix for CVE-2017-3143,
CVE-2017-3142, CVE-2017-3140

[ 1 ] Bug #1466193 – CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates
[ 2 ] Bug #1461302 – CVE-2017-3140 bind: Error processing RPZ rules leads to endless loop while handling query
[ 3 ] Bug #1466189 – CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade bind’ at the command line.
For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list —
To unsubscribe send an email to

AutorDanijel Kozinovic
Cert idNCERT-REF-2017-07-0070-ADV
More in Preporuke
Sigurnosni nedostaci programskog paketa bind-dyndb-ldap

Otkriveni su sigurnosni nedostaci u programskom paketu bind-dyndb-ldap za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju zaobilaženje sigurnosnih ograničenja...