Lucene search

K
oraclelinuxOracleLinuxELSA-2024-1782
HistoryApr 11, 2024 - 12:00 a.m.

bind and dhcp security update

2024-04-1100:00:00
linux.oracle.com
59
security update
dns parsing
cpu consumption
bind abi
dhcp
rebuild

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.05

Percentile

92.9%

bind
[32:9.11.36-11.1]

  • Speed up parsing of DNS messages with many different names (CVE-2023-4408)
  • Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387 CVE-2023-50868)
  • Do not use header_prev in expire_lru_headers
    dhcp
    [4.3.6]
  • Change bug tracker path
    [12:4.3.6-49.1]
  • Rebuild because of bind ABI changes related to CVE-2023-50387

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.05

Percentile

92.9%