Lucene search

K
cloudlinuxCloudLinuxCLSA-2024:1710437162
HistoryMar 14, 2024 - 5:26 p.m.

bind: Fix of 2 CVEs

2024-03-1417:26:05
repo.cloudlinux.com
17
fix
cpu exhaustion
dnssec
nsec3
internal tests
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

EPSS

0.05

Percentile

92.9%

  • CVE-2023-50387: Resolved CPU exhaustion from specially crafted DNSSEC-signed
    zone responses
  • CVE-2023-50868: Resolved CPU exhaustion from DNSSEC-signed zones using NSEC3
  • Enable internal tests by default

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

EPSS

0.05

Percentile

92.9%