Lucene search

K
redhatRedHatRHSA-2017:1202
HistoryMay 08, 2017 - 5:57 a.m.

(RHSA-2017:1202) Important: bind security update

2017-05-0805:57:05
access.redhat.com
68

0.002 Low

EPSS

Percentile

59.0%

The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.

Security Fix(es):

  • A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response. (CVE-2017-3139)

Note: This issue affected only the BIND versions as shipped with Red Hat Enterprise Linux 6. This issue did not affect any upstream versions of BIND.