Bug 57470 - BIND 9 vulnerability CVE-2024-1975
BIND 9 vulnerability CVE-2024-1975
Status: RESOLVED DUPLICATE of bug 57558
Product: UCS
Classification: Unclassified
Component: DNS
UCS 5.0
Other Linux
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
https://security-tracker.debian.org/t...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2024-07-26 11:22 CEST by Irina Kolesnikova
Modified: 2024-09-02 10:27 CEST (History)
4 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?: Yes
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2024072521000151
Bug group (optional): Security
Max CVSS v3 score: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Irina Kolesnikova univentionstaff 2024-07-26 11:22:13 CEST
UCS: 5.0-8 errata1085

dpkg -l |grep bind9
ii  bind9                                               1:9.11.5.P4+dfsg-5.1+deb10u11A~5.0.7.202405211119 amd64        Internet Domain Name Server
ii  bind9-host                                          1:9.11.5.P4+dfsg-5.1+deb10u11A~5.0.7.202405211119 amd64        DNS lookup utility (deprecated)
ii  bind9utils                                          1:9.11.5.P4+dfsg-5.1+deb10u11A~5.0.7.202405211119 amd64        Utilities for BIND
ii  libbind9-161:amd64                                  1:9.11.5.P4+dfsg-5.1+deb10u11A~5.0.7.202405211119 amd64        BIND9 Shared Library used by BIND

Our latest UCS 5 is running with BIND 9 version 9.11.5.P4+dfsg-5.1+deb10u11A, for which a vulnerability with a high severity has been reported by CVE.

https://www.cve.org/CVERecord?id=CVE-2024-1975
Comment 1 Jan-Luca Kiok univentionstaff 2024-09-02 10:27:37 CEST

*** This bug has been marked as a duplicate of bug 57558 ***