MGASA-2018-0353
Dashboard / Vulnerabilities / MGASA-2018-0353
Summary: Updated bind packages fix security vulnerability
Details: Updated bind packages fix security vulnerability: In ISC BIND, a defect in thie "deny-answer-aliases" feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Accidental or deliberate triggering of this defect will cause a REQUIRE assertion failure in named, causing the named process to stop execution and resulting in denial of service to clients (CVE-2018-5740). Note that only servers which have explicitly enabled the "deny-answer-aliases" feature are at risk and disabling the feature prevents exploitation.
References: https://advisories.mageia.org/MGASA-2018-0353.html, https://bugs.mageia.org/show_bug.cgi?id=23413, https://kb.isc.org/article/AA-01639, https://kb.isc.org/article/AA-01643
Affected packages
Package
Name: bind
Purl: pkg:rpm/mageia/bind?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
