MGASA-2018-0353

Source
https://advisories.mageia.org/MGASA-2018-0353.html
Import Source
https://advisories.mageia.org/MGASA-2018-0353.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2018-0353
Related
Published
2018-08-23T23:35:07Z
Modified
2018-08-23T23:10:03Z
Summary
Updated bind packages fix security vulnerability
Details

Updated bind packages fix security vulnerability:

In ISC BIND, a defect in thie "deny-answer-aliases" feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Accidental or deliberate triggering of this defect will cause a REQUIRE assertion failure in named, causing the named process to stop execution and resulting in denial of service to clients (CVE-2018-5740).

Note that only servers which have explicitly enabled the "deny-answer-aliases" feature are at risk and disabling the feature prevents exploitation.

References
Credits

Affected packages

Mageia:6 / bind

Package

Name
bind
Purl
pkg:rpm/mageia/bind?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.10.8.P1-1.mga6

Ecosystem specific

{
    "section": "core"
}