Lucene search

K
redhatRedHatRHSA-2017:2533
HistoryAug 24, 2017 - 4:19 a.m.

(RHSA-2017:2533) Moderate: bind security update

2017-08-2404:19:14
access.redhat.com
46

0.934 High

EPSS

Percentile

99.1%

The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.

Security Fix(es):

  • It was found that the lightweight resolver protocol implementation in BIND could enter an infinite recursion and crash when asked to resolve a query name which, when combined with a search list entry, exceeds the maximum allowable length. A remote attacker could use this flaw to crash lwresd or named when using the “lwres” statement in named.conf. (CVE-2016-2775)