Lucene search

K
osvGoogleOSV:DSA-3511-1
HistoryMar 09, 2016 - 12:00 a.m.

bind9 - security update

2016-03-0900:00:00
Google
osv.dev
15

EPSS

0.733

Percentile

98.1%

Two vulnerabilites have been discovered in ISC’s BIND DNS server.

  • CVE-2016-1285
    A maliciously crafted rdnc, a way to remotely administer a BIND server,
    operation can cause named to crash, resulting in denial of service.
  • CVE-2016-1286
    An error parsing DNAME resource records can cause named to crash,
    resulting in denial of service.

For the oldstable distribution (wheezy), these problems have been fixed
in version 1:9.8.4.dfsg.P1-6+nmu2+deb7u10.

For the stable distribution (jessie), these problems have been fixed in
version 1:9.9.5.dfsg-9+deb8u6.

For the testing (stretch) and unstable (sid) distributions, these
problems will be fixed soon.

We recommend that you upgrade your bind9 packages.