SUSE-SU-2017:1737-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1737-1
SUSE-SU-2017:1737-1
Summary: Security update for bind
Details: This update for bind fixes the following issues: - An attacker with the ability to send and receive messages to an authoritative DNS server was able to circumvent TSIG authentication of AXFR requests. A server that relied solely on TSIG keys for protection could be manipulated into (1) providing an AXFR of a zone to an unauthorized recipient and (2) accepting bogus Notify packets. [bsc#1046554, CVE-2017-3142] - An attacker who with the ability to send and receive messages to an authoritative DNS server and who had knowledge of a valid TSIG key name for the zone and service being targeted was able to manipulate BIND into accepting an unauthorized dynamic update. [bsc#1046555, CVE-2017-3143]
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171737-1/, https://bugzilla.suse.com/1046554, https://bugzilla.suse.com/1046555, https://www.suse.com/security/cve/CVE-2017-3142, https://www.suse.com/security/cve/CVE-2017-3143
Affected packages
Package
Name: bind
Purl: pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
