Lucene search

K
debianlists.debian.orgDEBIAN:DLA-3816-1:CEC5A
HistoryMay 17, 2024 - 6:05 p.m.

[SECURITY] [DLA 3816-1] bind9 security update

2024-05-1718:05:06
lists.debian.org
6
dns server
debian
cve-2023-50387
denial of service
cve-2023-50868
bind9

8.4 High

AI Score

Confidence

High

0.05 Low

EPSS

Percentile

92.9%


Debian LTS Advisory DLA-3816-1 [email protected]
https://www.debian.org/lts/security/ Santiago Ruano Rincón
May 17, 2024 https://wiki.debian.org/LTS

Package : bind9
Version : 1:9.11.5.P4+dfsg-5.1+deb10u11
CVE ID : CVE-2023-50387 CVE-2023-50868
Debian Bug :

Two vulnerabilities were discovered in BIND, a DNS server implementation, which
may result in denial of service.

CVE-2023-50387

Certain DNSSEC aspects of the DNS protocol allow remote attackers to cause
a denial of service via DNSSEC queries. This is known as the "KeyTrap"
issue.

CVE-2023-50868

The Closest Encloser Proof aspect of the DNS protocol allows remote
attackers to cause a denial of service via DNSSEC queries in a random
subdomain attack. This is known as the "NSEC3" issue.

For Debian 10 buster, these problems have been fixed in version
1:9.11.5.P4+dfsg-5.1+deb10u11.

We recommend that you upgrade your bind9 packages.

For the detailed security status of bind9 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/bind9

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS