[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2017:1737-1 -- SLES bind

ID: oval:org.secpod.oval:def:89044715Date: (C)2021-07-07   (M)2022-10-10
Class: PATCHFamily: unix




This update for bind fixes the following issues: - An attacker with the ability to send and receive messages to an authoritative DNS server was able to circumvent TSIG authentication of AXFR requests. A server that relied solely on TSIG keys for protection could be manipulated into providing an AXFR of a zone to an unauthorized recipient and accepting bogus Notify packets. [bsc#1046554, CVE-2017-3142] - An attacker who with the ability to send and receive messages to an authoritative DNS server and who had knowledge of a valid TSIG key name for the zone and service being targeted was able to manipulate BIND into accepting an unauthorized dynamic update. [bsc#1046555, CVE-2017-3143]

Platform:
SUSE Linux Enterprise Server 11 SP4
Product:
bind
Reference:
SUSE-SU-2017:1737-1
CVE-2017-3142
CVE-2017-3143
CVE    2
CVE-2017-3143
CVE-2017-3142
CPE    339
cpe:/a:isc:bind:9.7.6:p4
cpe:/a:isc:bind:9.7.6:p3
cpe:/a:isc:bind:9.6-esv-r6:b1
cpe:/a:isc:bind:9.7.6:p2
...

© SecPod Technologies