Opened 3 years ago
Closed 3 years ago
#17109 closed enhancement (fixed)
bind-9.18.7 bind9
Reported by: | Douglas R. Reno | Owned by: | Bruce Dubbs |
---|---|---|---|
Priority: | elevated | Milestone: | 11.3 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version
I know of 6 CVEs in this one - 4 high, and 2 medium, and all are remotely exploitable:
- CVE-2022-2795: Processing large delegations may severely degrade resolver performance https://kb.isc.org/docs/cve-2022-2795
- CVE-2022-2881: Buffer overread in statistics channel code https://kb.isc.org/docs/cve-2022-2881
- CVE-2022-2906: Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only) https://kb.isc.org/docs/cve-2022-2906
- CVE-2022-3080: BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly https://kb.isc.org/docs/cve-2022-3080
- CVE-2022-38177: Memory leak in ECDSA DNSSEC verification code https://kb.isc.org/docs/cve-2022-38177
- CVE-2022-38178: Memory leaks in EdDSA DNSSEC verification code https://kb.isc.org/docs/cve-2022-38178
Change History (4)
comment:1 by , 3 years ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 3 years ago
comment:3 by , 3 years ago
Fixed at commit b8007e8eb1236976a05443f4a30c74f35630c0c3
Will leave open until the security advisory is posted.
comment:4 by , 3 years ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
SA-11.2-012 filed. Closing.
Note:
See TracTickets
for help on using tickets.
9.18.7 released