[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2024:0590-1 -- SLES bind, python3-bind

ID: oval:org.secpod.oval:def:89051528Date: (C)2024-04-26   (M)2024-04-26
Class: PATCHFamily: unix




This update for bind fixes the following issues: Update to release 9.16.48: Feature Changes: * The IP addresses for B.ROOT-SERVERS.NET have been updated to 170.247.170.2 and 2801:1b8:10::b. Security Fixes: * Validating DNS messages containing a lot of DNSSEC signatures could cause excessive CPU load, leading to a denial-of-service condition. This has been fixed. [bsc#1219823] * Preparing an NSEC3 closest encloser proof could cause excessive CPU load, leading to a denial-of-service condition. This has been fixed. [bsc#1219826] * Parsing DNS messages with many different names could cause excessive CPU load. This has been fixed. [bsc#1219851] * Specific queries could cause named to crash with an assertion failure when nxdomain-redirect was enabled. This has been fixed. [bsc#1219852] * A bad interaction between DNS64 and serve-stale could cause named to crash with an assertion failure, when both of these features were enabled. This has been fixed. [bsc#1219853] * Query patterns that continuously triggered cache database maintenance could cause an excessive amount of memory to be allocated, exceeding max-cache-size and potentially leading to all available memory on the host running named being exhausted. This has been fixed. [bsc#1219854] Removed Features: * Support for using AES as the DNS COOKIE algorithm has been deprecated and will be removed in a future release. Please use the current default, SipHash-2-4, instead.

Platform:
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Server 15 SP4
Product:
bind
python3-bind
Reference:
SUSE-SU-2024:0590-1
CVE-2023-4408
CVE-2023-50387
CVE-2023-50868
CVE-2023-5517
CVE-2023-5679
CVE-2023-6516
CVE    6
CVE-2023-50387
CVE-2023-5517
CVE-2023-4408
CVE-2023-50868
...
CPE    4
cpe:/a:isc:bind
cpe:/a:python:python3-bind
cpe:/o:suse:suse_linux_enterprise_server:15:sp4
cpe:/o:suse:suse_linux_enterprise_desktop:15:sp4
...

© SecPod Technologies