MGASA-2015-0481
Dashboard / Vulnerabilities / MGASA-2015-0481
Summary: Updated bind packages fix security vulnerability
Details: An error in the parsing of incoming responses allows some records with an incorrect class to be accepted by BIND instead of being rejected as malformed. This can trigger a REQUIRE assertion failure when those records are subsequently cached. Intentional exploitation of this condition is possible and could be used as a denial-of-service vector against servers performing recursive queries (CVE-2015-8000).
References: https://advisories.mageia.org/MGASA-2015-0481.html, https://bugs.mageia.org/show_bug.cgi?id=17339, https://kb.isc.org/article/AA-01317, https://kb.isc.org/article/AA-01317
Affected packages
Package
Name: bind
Purl: pkg:rpm/mageia/bind?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
