AVG-1056 log
| Package | bind |
| Status | Fixed |
| Severity | Medium |
| Type | multiple issues |
| Affected | 9.14.6-1 |
| Fixed | 9.14.7-1 |
| Current | 9.20.16-1 [extra] |
| Ticket | None |
| Created | Wed Oct 30 10:01:49 2019 |
| Issue | Severity | Remote | Type | Description |
|---|---|---|---|---|
| CVE-2019-6476 | Medium | Yes | Denial of service | An error in QNAME minimization code can cause bind before 9.14.7 and 9.15.5 to exit with an assertion failure. |
| CVE-2019-6475 | Medium | Yes | Content spoofing | A security issue has been found in Bind before 9.14.7 and 9.15.5, where a mirror zone validity checking can allow zone data to be spoofed. |
| References |
|---|
https://seclists.org/oss-sec/2019/q4/27 |