Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 728972

Summary: net-dns/bind-9.16.4 bump request due to CVE-2020-8618 and CVE-2020-8619
Product: Gentoo Security Reporter: Krzysztof Olędzki <ole+gentoo>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: idl0r, ole+gentoo, zlogene
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://downloads.isc.org/isc/bind9/9.16.4/doc/arm/html/notes.html#security-fixes
Whiteboard:
Package list:
Runtime testing required: ---

Description Krzysztof Olędzki 2020-06-21 03:35:26 UTC
net-dns/bind-9.16.3 is affected by two security issues:

It is possible to trigger an assertion when attempting to fill an oversized TCP buffer. This was disclosed in CVE-2020-8618. [GL #1850]

It is possible to trigger an INSIST failure when a zone with an interior wildcard label was queried in a certain pattern. This was disclosed in CVE-2020-8619. [GL #1111] [GL #1718]


Reproducible: Always
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-21 10:47:43 UTC
Thanks for your report. This is already being tracked as bug 728590.

*** This bug has been marked as a duplicate of bug 728590 ***