SB2016012014 - Input validation error in bind (Alpine package)
Published: January 20, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2015-8705)
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=b527cfa00a7793b4db08311ff32263dce31eeae7
- https://git.alpinelinux.org/aports/commit/?id=1cff01908c342a676deca5a1d7261020c6241d2d
- https://git.alpinelinux.org/aports/commit/?id=efcb126bc36e67ceb010f9ca31daf5427d06efef
- https://git.alpinelinux.org/aports/commit/?id=dff85e5b601949d4052c57624e404e5788eec9d0
- https://git.alpinelinux.org/aports/commit/?id=a4e3789df52208f238990273e87a14b5556b9f69