[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2017:1736-1 -- SLES bind

ID: oval:org.secpod.oval:def:89045018Date: (C)2021-07-20   (M)2022-08-31
Class: PATCHFamily: unix




This update for bind fixes the following issues: - An attacker with the ability to send and receive messages to an authoritative DNS server was able to circumvent TSIG authentication of AXFR requests. A server that relied solely on TSIG keys for protection could be manipulated into providing an AXFR of a zone to an unauthorized recipient and accepting bogus Notify packets. [bsc#1046554, CVE-2017-3142] - An attacker who with the ability to send and receive messages to an authoritative DNS server and who had knowledge of a valid TSIG key name for the zone and service being targeted was able to manipulate BIND into accepting an unauthorized dynamic update. [bsc#1046555, CVE-2017-3143]

Platform:
SUSE Linux Enterprise Server 12 SP2
Product:
bind
Reference:
SUSE-SU-2017:1736-1
CVE-2017-3142
CVE-2017-3143
CVE    2
CVE-2017-3143
CVE-2017-3142
CPE    2
cpe:/o:suse:suse_linux_enterprise_server:12:sp2
cpe:/a:isc:bind

© SecPod Technologies