MGASA-2021-0110
Dashboard / Vulnerabilities / MGASA-2021-0110
Summary: Updated bind packages fix security vulnerability
Details: A buffer overflow vulnerability was discovered in the SPNEGO implementation affecting the GSSAPI security policy negotiation in BIND, which could result in denial of service (daemon crash), or potentially the execution of arbitrary code (CVE-2020-8625). The default configuration is not vulnerable to this issue, but it is if the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration options are set.
References: https://advisories.mageia.org/MGASA-2021-0110.html, https://bugs.mageia.org/show_bug.cgi?id=28394, https://kb.isc.org/docs/cve-2020-8625, https://www.debian.org/security/2021/dsa-4857
Affected packages
Package
Name: bind
Purl: pkg:rpm/mageia/bind?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
