Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-1789

Опубликовано: 11 апр. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-1789: bind security update (IMPORTANT)

bind [32:9.16.23-14.4]

  • Rebuild with correct z-stream tag again

[32:9.16.23-14.3]

  • Rebuild together with bind-dyndb-ldap to adjust ABI changes

[32:9.16.23-14.2]

  • Import tests for large DNS messages fix
  • Add downstream change complementing CVE-2023-50387

[32:9.16.23-14.1]

  • Prevent increased CPU load on large DNS messages (CVE-2023-4408)
  • Prevent assertion failure when nxdomain-redirect is used with RFC 1918 reverse zones (CVE-2023-5517)
  • Prevent assertion failure if DNS64 and serve-stale is used (CVE-2023-5679)
  • Specific recursive query patterns may lead to an out-of-memory condition (CVE-2023-6516)
  • Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387 CVE-2023-50868)

bind-dyndb-ldap [11.9-8.3]

  • Rebuild with correct z-stream tag again

[11.9-8.2]

  • Rebuild required for BIND changes for KeyTrap change (CVE-2023-50387)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

bind

9.16.23-14.el9_3.4

bind-chroot

9.16.23-14.el9_3.4

bind-devel

9.16.23-14.el9_3.4

bind-dnssec-doc

9.16.23-14.el9_3.4

bind-dnssec-utils

9.16.23-14.el9_3.4

bind-doc

9.16.23-14.el9_3.4

bind-dyndb-ldap

11.9-8.el9_3.3

bind-libs

9.16.23-14.el9_3.4

bind-license

9.16.23-14.el9_3.4

bind-utils

9.16.23-14.el9_3.4

python3-bind

9.16.23-14.el9_3.4

Oracle Linux x86_64

bind

9.16.23-14.el9_3.4

bind-chroot

9.16.23-14.el9_3.4

bind-devel

9.16.23-14.el9_3.4

bind-dnssec-doc

9.16.23-14.el9_3.4

bind-dnssec-utils

9.16.23-14.el9_3.4

bind-doc

9.16.23-14.el9_3.4

bind-dyndb-ldap

11.9-8.el9_3.3

bind-libs

9.16.23-14.el9_3.4

bind-license

9.16.23-14.el9_3.4

bind-utils

9.16.23-14.el9_3.4

python3-bind

9.16.23-14.el9_3.4

Связанные уязвимости

suse-cvrf
больше 1 года назад

Security update for bind

suse-cvrf
больше 1 года назад

Security update for bind

rocky
около 1 года назад

Important: bind security update

rocky
около 1 года назад

Important: bind9.16 security update

oracle-oval
около 1 года назад

ELSA-2024-2551: bind security update (IMPORTANT)