Lucene search

K
osvGoogleOSV:DLA-270-1
HistoryJul 11, 2015 - 12:00 a.m.

bind9 - security update

2015-07-1100:00:00
Google
osv.dev
14

EPSS

0.157

Percentile

96.0%

A vulnerability has been found in the Internet Domain Name Server bind9:

  • CVE-2015-4620
    Breno Silveira Soares of Servico Federal de Processamento de Dados (SERPRO)
    discovered that the BIND DNS server is prone to a denial of service
    vulnerability. A remote attacker who can cause a validating resolver
    to query a zone containing specifically constructed contents can
    cause the resolver to terminate with an assertion failure, resulting
    in a denial of service to clients relying on the resolver.

For the squeeze distribution, these issues have been fixed in version
9.7.3.dfsg-1~squeeze15 of bind9.

We recommend that you upgrade your bind9 packages.