Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.885732
Categoría:Fedora Local Security Checks
Título:Fedora: Security Advisory (FEDORA-2024-21310568fa)
Resumen:The remote host is missing an update for the 'bind, bind-dyndb-ldap' package(s) announced via the FEDORA-2024-21310568fa advisory.
Descripción:Summary:
The remote host is missing an update for the 'bind, bind-dyndb-ldap' package(s) announced via the FEDORA-2024-21310568fa advisory.

Vulnerability Insight:
# Security Fixes

- Validating DNS messages containing a lot of DNSSEC signatures could cause excessive CPU load, leading to a denial-of-service condition. This has been fixed. ([CVE-2023-50387]([link moved to references]))

ISC would like to thank Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner from the German National Research Center for Applied Cybersecurity ATHENE for bringing this vulnerability to our attention. [GL #4424]

- Parsing DNS messages with many different names could cause excessive CPU load. This has been fixed. ([CVE-2023-4408]([link moved to references]))

ISC would like to thank Shoham Danino from Reichman University, Anat Bremler-Barr from Tel-Aviv University, Yehuda Afek from Tel-Aviv University, and Yuval Shavitt from Tel-Aviv University for bringing this vulnerability to our attention. [GL #4234]

- Specific queries could cause named to crash with an assertion failure when nxdomain-redirect was enabled. This has been fixed. ([CVE-2023-5517]([link moved to references])) [GL #4281]

- A bad interaction between DNS64 and serve-stale could cause named to crash with an assertion failure, when both of these features were enabled. This has been fixed. ([CVE-2023-5679]([link moved to references])) [GL #4334]

- Under certain circumstances, the DNS-over-TLS client code incorrectly attempted to process more than one DNS message at a time, which could cause named to crash with an assertion failure. This has been fixed. [GL #4487]

- Full [Release notes]([link moved to references])

## Related blog post

- [BIND 9 Security Release and Multi-Vendor Vulnerability Handling, CVE-2023-50387 and CVE-2023-50868]([link moved to references])

Affected Software/OS:
'bind, bind-dyndb-ldap' package(s) on Fedora 39.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2023-4408
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/
CVE-2023-4408
https://kb.isc.org/docs/cve-2023-4408
http://www.openwall.com/lists/oss-security/2024/02/13/1
Common Vulnerability Exposure (CVE) ID: CVE-2023-50387
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/
https://access.redhat.com/security/cve/CVE-2023-50387
https://bugzilla.suse.com/show_bug.cgi?id=1219823
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html
https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1
https://kb.isc.org/docs/cve-2023-50387
https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-50387
https://news.ycombinator.com/item?id=39367411
https://news.ycombinator.com/item?id=39372384
https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/
https://www.athene-center.de/aktuelles/key-trap
https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdf
https://www.isc.org/blogs/2024-bind-security-release/
https://www.securityweek.com/keytrap-dns-attack-could-disable-large-parts-of-internet-researchers/
https://www.theregister.com/2024/02/13/dnssec_vulnerability_internet/
https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html
https://lists.debian.org/debian-lts-announce/2024/05/msg00011.html
http://www.openwall.com/lists/oss-security/2024/02/16/2
http://www.openwall.com/lists/oss-security/2024/02/16/3
Common Vulnerability Exposure (CVE) ID: CVE-2023-50868
https://access.redhat.com/security/cve/CVE-2023-50868
https://bugzilla.suse.com/show_bug.cgi?id=1219826
https://datatracker.ietf.org/doc/html/rfc5155
https://kb.isc.org/docs/cve-2023-50868
Common Vulnerability Exposure (CVE) ID: CVE-2023-5517
CVE-2023-5517
https://kb.isc.org/docs/cve-2023-5517
Common Vulnerability Exposure (CVE) ID: CVE-2023-5679
CVE-2023-5679
https://kb.isc.org/docs/cve-2023-5679
Common Vulnerability Exposure (CVE) ID: CVE-2023-6516
CVE-2023-6516
https://kb.isc.org/docs/cve-2023-6516
CopyrightCopyright (C) 2024 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.