Release Info

Advisory: CLSA-2024:1709562964

OS: Ubuntu 18.04 ELS

Public date: 2024-03-04 09:36:07

Project: bind9

Version: 1:9.11.3+dfsg-1ubuntu1.18+tuxcare.els3

Errata link: https://errata.tuxcare.com/els_os/ubuntu18.04els/CLSA-2024-1709562964.html

Changelog

* SECURITY UPDATE: KeyTrap denial of service vulnerability - debian/patches/CVE-2023-50387-20230-50868.patch: Fix DNSSEC verification complexity issue by updating verification function signatures. - debian/patches/CVE-2023-50387-fix-1.patch: Allow the original CVE-2023-50387 patch to work if multiple threads support is disabled. - debian/patches/CVE-2023-50387-fix-2.patch: Fix a leak. - CVE-2023-50387 - CVE-2023-50868 * a test suite was activated.

Update

Update command: apt-get update apt-get --only-upgrade install bind9*

Packages list

bind9_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb bind9-doc_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_all.deb bind9-host_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb bind9utils_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb dnsutils_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libbind-dev_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libbind-export-dev_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libbind9-160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libdns-export1100_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libdns1100_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libirs-export160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libirs160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libisc-export169_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libisc169_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libisccc-export160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libisccc160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libisccfg-export160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb libisccfg160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb liblwres160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els3_amd64.deb

CVEs

CVE-2023-50387
CVE-2023-50868