Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Bind
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Bind
ID: USN-4929-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10, Ubuntu 21.04
Datum: Do, 29. April 2021, 22:29
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25214
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25215
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25216
Applikationen: BIND

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============0272363985459117708==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="mp24m0AeQKt4PepfJS61eoOQFIf69MCMh"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--mp24m0AeQKt4PepfJS61eoOQFIf69MCMh
Content-Type: multipart/mixed;
boundary="ci0hxC3w7kpljnGXLvr3PtYR06lLmCXJH";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <0674be36-4b92-797f-25a1-8c3b116c266f@canonical.com>
Subject: [USN-4929-1] Bind vulnerabilities

--ci0hxC3w7kpljnGXLvr3PtYR06lLmCXJH
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4929-1
April 29, 2021

bind9 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.04
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in Bind.

Software Description:
- bind9: Internet Domain Name Server

Details:

Greg Kuechle discovered that Bind incorrectly handled certain incremental
zone updates. A remote attacker could possibly use this issue to cause Bind
to crash, resulting in a denial of service. (CVE-2021-25214)

Siva Kakarla discovered that Bind incorrectly handled certain DNAME
records. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. (CVE-2021-25215)

It was discovered that Bind incorrectly handled GSSAPI security policy
negotiation. A remote attacker could use this issue to cause Bind to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-25216)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
bind9 1:9.16.8-1ubuntu3.1

Ubuntu 20.10:
bind9 1:9.16.6-3ubuntu1.2

Ubuntu 20.04 LTS:
bind9 1:9.16.1-0ubuntu2.8

Ubuntu 18.04 LTS:
bind9 1:9.11.3+dfsg-1ubuntu1.15

Ubuntu 16.04 LTS:
bind9 1:9.10.3.dfsg.P4-8ubuntu1.19

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4929-1
CVE-2021-25214, CVE-2021-25215, CVE-2021-25216

Package Information:
https://launchpad.net/ubuntu/+source/bind9/1:9.16.8-1ubuntu3.1
https://launchpad.net/ubuntu/+source/bind9/1:9.16.6-3ubuntu1.2
https://launchpad.net/ubuntu/+source/bind9/1:9.16.1-0ubuntu2.8
https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.15
https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.19


--ci0hxC3w7kpljnGXLvr3PtYR06lLmCXJH--

--mp24m0AeQKt4PepfJS61eoOQFIf69MCMh
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmCKpPwACgkQZWnYVadE
vpMfrw//dtVjS1pbRZaeWBC5DRn4PJzDj/QT/776yA5cct/T/vIFtboQYVP1goTz
JT6PC6oylWD0qdqfWwK6KjvMHit3RaJ66R2DLG0zLD+p6NGywkOU2ldC46EYqoi+
t6IJKdeN5cWFogRqKMaOdfdrclpXIdfsINNBmbg5VjEL3jzOt4k5otLkIOmYX0vl
kMYI7zZ/X9foNR9pEp3FiwRzYK5/93/lCT3K4r8aVXYkJRW/6Yfs82QrAQ3MX4OR
g5E7jN4WAQmDeb3QHvimAhiDLcX6eVEk6TeFIdAMpTxi6VYvRKYpwh+wrm7aTDrH
w+SVsJ4I2WdBieGXsGRRm9HmA0NmreaGN2kdNGBxHGssTLw6GWMY+GvmEHpo1rTT
XwGxY/93KceM2ubQenemVvztn+LE4a2jJtwWuPOqvAvPHh2bE8Mb4hfbh3EvFFM8
2MpcTsKXqmmPqeADAb+Lgp6t+vFR2u++gT2r++9gr+n/rmJ+ClngDyuIE3KH3mi5
pC22rPbbsjyirOvD2Fismp7rtq9ClPgLWS1iNXPKjeF1phMTpFNNVcQ6jSKcLVaA
G5eQRnTXXRB83bcKhSsT00CkVxo7PHQqdUdZiejiccB9M1kpiFjph0kwuK9ArDeZ
zrzih19N6R8CIENFTvZVXQ11R1OJGqEjBBzVUMmKJTAZZAPuQ9s=
=p2Hd
-----END PGP SIGNATURE-----

--mp24m0AeQKt4PepfJS61eoOQFIf69MCMh--


--===============0272363985459117708==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============0272363985459117708==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung