MGASA-2021-0220

Source
https://advisories.mageia.org/MGASA-2021-0220.html
Import Source
https://advisories.mageia.org/MGASA-2021-0220.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0220
Related
Published
2021-05-23T18:45:17Z
Modified
2021-05-23T17:42:22Z
Summary
Updated bind packages fix security vulnerabilities
Details

A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly(CVE-2021-25214). Mageia 7 version not affected.

An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself (CVE-2021-25215). This affects both versions.

A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack (CVE-2021-25216). Mageia 7 version not affected.

References
Credits

Affected packages

Mageia:7 / bind

Package

Name
bind
Purl
pkg:rpm/mageia/bind?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.11.6-1.4.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / bind

Package

Name
bind
Purl
pkg:rpm/mageia/bind?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.11.31-1.1.mga8

Ecosystem specific

{
    "section": "core"
}