SUSE-SU-2022:3499-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3499-1
SUSE-SU-2022:3499-1
Summary: Security update for bind
Details: This update for bind fixes the following issues: - CVE-2022-2795: Fixed potential performance degredation due to missing database lookup limits when processing large delegations (bsc#1203614). - CVE-2022-38177: Fixed a memory leak that could be externally triggered in the DNSSEC verification code for the ECDSA algorithm (bsc#1203619). - CVE-2022-38178: Fixed memory leaks that could be externally triggered in the DNSSEC verification code for the EdDSA algorithm (bsc#1203620).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223499-1/, https://bugzilla.suse.com/1203614, https://bugzilla.suse.com/1203619, https://bugzilla.suse.com/1203620, https://www.suse.com/security/cve/CVE-2022-2795, https://www.suse.com/security/cve/CVE-2022-38177, https://www.suse.com/security/cve/CVE-2022-38178
Affected packages
Package
Name: bind
Purl: pkg:rpm/suse/bind&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
