• [SECURITY] [DSA 4752-1] bind9 security update

    From Salvatore Bonaccorso@21:1/5 to All on Thu Aug 27 20:10:01 2020
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4752-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 27, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : bind9
    CVE ID : CVE-2020-8619 CVE-2020-8622 CVE-2020-8623 CVE-2020-8624
    Debian Bug : 966497

    Several vulnerabilities were discovered in BIND, a DNS server
    implementation.

    CVE-2020-8619

    It was discovered that an asterisk character in an empty non-
    terminal can cause an assertion failure, resulting in denial
    of service.

    CVE-2020-8622

    Dave Feldman, Jeff Warren, and Joel Cunningham reported that a
    truncated TSIG response can lead to an assertion failure, resulting
    in denial of service.

    CVE-2020-8623

    Lyu Chiy reported that a flaw in the native PKCS#11 code can lead
    to a remotely triggerable assertion failure, resulting in denial
    of service.

    CVE-2020-8624

    Joop Boonen reported that update-policy rules of type "subdomain"
    are enforced incorrectly, allowing updates to all parts of the zone
    along with the intended subdomain.

    For the stable distribution (buster), these problems have been fixed in
    version 1:9.11.5.P4+dfsg-5.1+deb10u2.

    We recommend that you upgrade your bind9 packages.

    For the detailed security status of bind9 please refer to its security
    tracker page at:
    https://security-tracker.debian.org/tracker/bind9

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl9H9LBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Riow//eYx52gDQkiERYSEFJbSK34AzF5Ee3W8JYh1BG4PFagvR/y3hwddyFEkR pHlq/t78TPWi9oQ3j8uuQL0VLMA+8jyaNXA0h6BMs/3VKzGktFyINdKPBPIghT2w 2tugfgjK1MR0LZ27rcE86I1QoyFy+jHMmd03R0B0AQPWYkjp+2sp5nxskFVM9jXO 8emXIzT3IZns8WSS7xCZOqE6D40Vk/3hP5IXDXIbHHFUgl6jCEpPHJBHCgrtw9HZ Or/EQgy4y+QUZNqsPw93kxc7cwVWhauW/PX9VZ1HWnfMIWEZX9K8fmYPHlj4dJUa 1G45uTtYT7VaLvs+N7j1UulII+f1ZT9rrljasVKfbmALt+mp28/LzzcCCBMYohkK Ka30MmBu5yZnn36LNWGwaOO5D+cCHsc58awKu3C5wUG/QMBjT+dYlhkbUbllpZVj vMMXjnrefdkCLy7LEDAul1NLgxWcSWzcQ0SyNEfu9IajtA94unFMwNzFmQb7ykql WMkHTg+7mSdPCxOI+0g9+w+pKZFdBGZxXu76cV8FB1BmRitsM8XYrtBGO9uWvkI9 hIm7pHhyJB0E008qo+cKutpnvruLZLBUCutUuNHZAirq+zaHjoVDSxiqPWEJ9jdR Sx85bc7+6f1daR04r5ay/mCuWPTQYrM1VyBsFnAvGxWoznHnmbk=
    =kUyE
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)