SUSE-SU-2021:1469-1
Dashboard / Vulnerabilities / SUSE-SU-2021:1469-1
SUSE-SU-2021:1469-1
Summary: Security update for bind
Details: This update for bind fixes the following issues: - CVE-2021-25214: Fixed a broken inbound incremental zone update (IXFR) which could have caused named to terminate unexpectedly (bsc#1185345). - CVE-2021-25215: Fixed an assertion check which could have failed while answering queries for DNAME records that required the DNAME to be processed to resolve itself (bsc#1185345). - CVE-2021-25216: Fixed an issue where policy negotiation can be targeted by a buffer overflow attack (bsc#1185345). - MD5 warning message using host, dig, nslookup (bind-utils) with FIPS enabled (bsc#1181495).
References: https://www.suse.com/support/update/announcement/2021/suse-su-20211469-1/, https://bugzilla.suse.com/1181495, https://bugzilla.suse.com/1185345, https://www.suse.com/security/cve/CVE-2021-25214, https://www.suse.com/security/cve/CVE-2021-25215, https://www.suse.com/security/cve/CVE-2021-25216
Affected packages
Package
Name: bind
Purl: pkg:rpm/suse/bind&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
