1 |
type: security |
2 |
subject: Updated bind packages fix security vulnerabilities |
3 |
CVE: |
4 |
- CVE-2018-5743 |
5 |
- CVE-2019-6471 |
6 |
src: |
7 |
7: |
8 |
core: |
9 |
- bind-9.11.6-1.1.mga7 |
10 |
description: | |
11 |
Updated bind packages fix security vulnerabilities |
12 |
|
13 |
Limiting simultaneous TCP clients is ineffective (CVE-2018-5743) |
14 |
|
15 |
Race condition when discarding malformed packets can cause bind to |
16 |
exit with assertion failure (CVE-2019-6471) |
17 |
|
18 |
In addition to those two security issues, this package releases also |
19 |
fixes two additional issues: |
20 |
- a missing conflict tag between old bind and bnew ind-utils subpackages, |
21 |
preventing upgrade due to a file conflict |
22 |
- missing root.key file, despite this one being refered in default |
23 |
configuration |
24 |
references: |
25 |
- https://bugs.mageia.org/show_bug.cgi?id=24422 |
26 |
- https://access.redhat.com/errata/RHSA-2019:1294 |
27 |
- https://access.redhat.com/errata/RHSA-2019:1714 |
28 |
ID: MGASA-2019-0299 |