[CLSA-2021:1632261705] Fixed CVEs in bind: CVE-2021-25214, CVE-2021-25216, CVE-2021-25215
Type:
security
Severity:
Moderate
Release date:
2021-09-21
Description:
- A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly (CVE-2021-25214) - An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself (CVE-2021-25215) - A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack (CVE-2021-25216)
Updated packages:
  • bind-sdb-9.8.2-0.68.rc1.el6_10.10.cloudlinux.els.x86_64.rpm
    sha:a033999d6a9550e1fbebef65658df3b4853438ab
  • bind-libs-9.8.2-0.68.rc1.el6_10.10.cloudlinux.els.x86_64.rpm
    sha:7935f5bdb9b748b46b4feea1e5e4775398f1d435
  • bind-devel-9.8.2-0.68.rc1.el6_10.10.cloudlinux.els.x86_64.rpm
    sha:4e14fee27e3fec6371b8b8cec55ccee33aaab9ef
  • bind-9.8.2-0.68.rc1.el6_10.10.cloudlinux.els.x86_64.rpm
    sha:1b2c2f019690762712619ceca3a9f809aa3b38a8
  • bind-utils-9.8.2-0.68.rc1.el6_10.10.cloudlinux.els.x86_64.rpm
    sha:03267c6b26391b8aa9fe8c70a52dbf8f5724c131
  • bind-chroot-9.8.2-0.68.rc1.el6_10.10.cloudlinux.els.x86_64.rpm
    sha:56af25d2507dd1306aedeb7cc83b1545a681ffa1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.