Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-7790

Опубликовано: 15 нояб. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-7790: bind security update (MODERATE)

[32:9.11.36-5]

  • Fix memory leak in ECDSA verify processing (CVE-2022-38177)
  • Fix memory leak in EdDSA verify processing (CVE-2022-38178)

[32:9.11.36-4]

  • Tighten cache protection against record from forwarders (CVE-2021-25220)
  • Include test of forwarders

[32:9.11.36-2]

  • Reduce memory used per-view on machine with few processors (#2030239)

[32:9.11.36-2]

  • Rebuilt on a new side-tag (#2013993)

[32:9.11.36-1]

  • Update to 9.11.36

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

bind

9.11.36-5.el8

bind-chroot

9.11.36-5.el8

bind-devel

9.11.36-5.el8

bind-export-devel

9.11.36-5.el8

bind-export-libs

9.11.36-5.el8

bind-libs

9.11.36-5.el8

bind-libs-lite

9.11.36-5.el8

bind-license

9.11.36-5.el8

bind-lite-devel

9.11.36-5.el8

bind-pkcs11

9.11.36-5.el8

bind-pkcs11-devel

9.11.36-5.el8

bind-pkcs11-libs

9.11.36-5.el8

bind-pkcs11-utils

9.11.36-5.el8

bind-sdb

9.11.36-5.el8

bind-sdb-chroot

9.11.36-5.el8

bind-utils

9.11.36-5.el8

python3-bind

9.11.36-5.el8

Oracle Linux x86_64

bind

9.11.36-5.el8

bind-chroot

9.11.36-5.el8

bind-devel

9.11.36-5.el8

bind-export-devel

9.11.36-5.el8

bind-export-libs

9.11.36-5.el8

bind-libs

9.11.36-5.el8

bind-libs-lite

9.11.36-5.el8

bind-license

9.11.36-5.el8

bind-lite-devel

9.11.36-5.el8

bind-pkcs11

9.11.36-5.el8

bind-pkcs11-devel

9.11.36-5.el8

bind-pkcs11-libs

9.11.36-5.el8

bind-pkcs11-utils

9.11.36-5.el8

bind-sdb

9.11.36-5.el8

bind-sdb-chroot

9.11.36-5.el8

bind-utils

9.11.36-5.el8

python3-bind

9.11.36-5.el8

Связанные CVE

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 3 лет назад

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.

CVSS3: 6.8
redhat
больше 3 лет назад

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.

CVSS3: 6.8
nvd
около 3 лет назад

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.

CVSS3: 6.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 6.8
debian
около 3 лет назад

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Support ...