Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:2502-1

Опубликовано: 01 окт. 2019
Источник: suse-cvrf

Описание

Security update for bind

This update for bind fixes the following issues:

Security issues fixed:

  • CVE-2019-6465: Fixed an issue where controls for zone transfers may not be properly applied to Dynamically Loadable Zones (bsc#1126069).
  • CVE-2019-6471: Fixed a reachable assert in dispatch.c. (bsc#1138687)
  • CVE-2018-5745: Fixed a denial of service vulnerability if a trust anchor rolls over to an unsupported key algorithm when using managed-keys (bsc#1126068).
  • CVE-2018-5743: Fixed a denial of service vulnerability which could be caused by to many simultaneous TCP connections (bsc#1133185).
  • CVE-2018-5740: Fixed a denial of service vulnerability in the 'deny-answer-aliases' feature (bsc#1104129).

Non-security issues fixed:

  • Don't rely on /etc/insserv.conf anymore for proper dependencies against nss-lookup.target in named.service and lwresd.service (bsc#1118367, bsc#1118368).
  • Fix FIPS related regression (bsc#1128220).

Список пакетов

Image SLES12-SP4-Azure-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-GCE-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-OCI-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-Azure
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-Azure-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-EC2-HVM
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-GCE
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-GCE-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP4-SAP-OCI-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-Azure-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-Azure-Basic-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-Azure-HPC-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-Azure-HPC-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-Azure-SAP-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-Azure-SAP-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-Azure-Standard-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-EC2-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-EC2-ECS-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-EC2-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-EC2-SAP-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-EC2-SAP-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-GCE-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-GCE-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-GCE-SAP-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-GCE-SAP-On-Demand
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-OCI-BYOS-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
bind-utils-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
SUSE Linux Enterprise Desktop 12 SP4
bind-utils-9.11.2-3.10.1
libbind9-160-9.11.2-3.10.1
libdns169-9.11.2-3.10.1
libirs160-9.11.2-3.10.1
libisc166-9.11.2-3.10.1
libisc166-32bit-9.11.2-3.10.1
libisccc160-9.11.2-3.10.1
libisccfg160-9.11.2-3.10.1
liblwres160-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
SUSE Linux Enterprise Server 12 SP4
bind-9.11.2-3.10.1
bind-chrootenv-9.11.2-3.10.1
bind-doc-9.11.2-3.10.1
bind-utils-9.11.2-3.10.1
libbind9-160-9.11.2-3.10.1
libdns169-9.11.2-3.10.1
libirs160-9.11.2-3.10.1
libisc166-9.11.2-3.10.1
libisc166-32bit-9.11.2-3.10.1
libisccc160-9.11.2-3.10.1
libisccfg160-9.11.2-3.10.1
liblwres160-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
bind-9.11.2-3.10.1
bind-chrootenv-9.11.2-3.10.1
bind-doc-9.11.2-3.10.1
bind-utils-9.11.2-3.10.1
libbind9-160-9.11.2-3.10.1
libdns169-9.11.2-3.10.1
libirs160-9.11.2-3.10.1
libisc166-9.11.2-3.10.1
libisc166-32bit-9.11.2-3.10.1
libisccc160-9.11.2-3.10.1
libisccfg160-9.11.2-3.10.1
liblwres160-9.11.2-3.10.1
python-bind-9.11.2-3.10.1
SUSE Linux Enterprise Software Development Kit 12 SP4
bind-devel-9.11.2-3.10.1

Описание

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-Azure-BYOS:python-bind-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:python-bind-9.11.2-3.10.1

Ссылки

Описание

By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-Azure-BYOS:python-bind-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:python-bind-9.11.2-3.10.1

Ссылки

Описание

"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-Azure-BYOS:python-bind-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:python-bind-9.11.2-3.10.1

Ссылки

Описание

Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-Azure-BYOS:python-bind-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:python-bind-9.11.2-3.10.1

Ссылки

Описание

A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-Azure-BYOS:python-bind-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:bind-utils-9.11.2-3.10.1
Image SLES12-SP4-EC2-HVM-BYOS:python-bind-9.11.2-3.10.1

Ссылки
Уязвимость SUSE-SU-2019:2502-1