Bug 57558 - bind9: Multiple issues (5.0)
bind9: Multiple issues (5.0)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 5.0
All Linux
: P3 normal (vote)
: UCS 5.0-8-errata
Assigned To: Quality Assurance
Julia Bremer
:
: 57470 57471 (view as bug list)
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2024-09-02 09:26 CEST by Quality Assurance
Modified: 2024-09-04 17:51 CEST (History)
2 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2024-09-02 09:26:17 CEST
New Debian bind9 1:9.11.5.P4+dfsg-5.1+deb10u13A~5.0.8.202409020923 fixes:
This update addresses the following issues:
1:9.11.5.P4+dfsg-5.1+deb10u13 (Tue, 20 Aug 2024 09:02:23 +0200)
* Fix assertion failure in CVE-2023-4408 backport.
1:9.11.5.P4+dfsg-5.1+deb10u12 (Wed, 14 Aug 2024 11:31:05 +0200)
* CVE-2024-1975
* CVE-2024-1737
* CVE-2023-4408
* Update symbols file for dropped symbols.
Comment 1 Quality Assurance univentionstaff 2024-09-02 10:00:32 CEST
--- mirror/ftp/pool/main/b/bind9/bind9_9.11.5.P4+dfsg-5.1+deb10u11A~5.0.7.202405211119.dsc
+++ apt/ucs_5.0-0-errata5.0-8/source/bind9_9.11.5.P4+dfsg-5.1+deb10u13A~5.0.8.202409020923.dsc
@@ -1,4 +1,4 @@
-1:9.11.5.P4+dfsg-5.1+deb10u11A~5.0.7.202405211119 [Tue, 21 May 2024 11:19:55 -0000] Univention builddaemon <buildd@univention.de>:
+1:9.11.5.P4+dfsg-5.1+deb10u13A~5.0.8.202409020923 [Mon, 02 Sep 2024 09:26:26 -0000] Univention builddaemon <buildd@univention.de>:
 
   * UCS auto build. The following patches have been applied to the original source package
     0001-Bug-22478-build-bind-with-libdb4.8.patch
@@ -19,6 +19,17 @@
     0017-Bug-51786-fix-apparmor-profile.patch
     0018-Bug-55163-fix-resolver-priming-query.quilt
 
+1:9.11.5.P4+dfsg-5.1+deb10u13 [Tue, 20 Aug 2024 09:02:23 +0200] Emilio Pozuelo Monfort <pochu@debian.org>:
+
+  * Fix assertion failure in CVE-2023-4408 backport.
+
+1:9.11.5.P4+dfsg-5.1+deb10u12 [Wed, 14 Aug 2024 11:31:05 +0200] Emilio Pozuelo Monfort <pochu@debian.org>:
+
+  * CVE-2024-1975
+  * CVE-2024-1737
+  * CVE-2023-4408
+  * Update symbols file for dropped symbols.
+
 1:9.11.5.P4+dfsg-5.1+deb10u11 [Fri, 17 May 2024 12:43:53 -0300] Santiago Ruano Rincón <santiago@freexian.com>:
 
   * Non-maintainer upload by the LTS Team.

<http://piuparts.knut.univention.de/5.0-8/#5446780078575389329>
Comment 2 Jan-Luca Kiok univentionstaff 2024-09-02 10:27:33 CEST
*** Bug 57471 has been marked as a duplicate of this bug. ***
Comment 3 Jan-Luca Kiok univentionstaff 2024-09-02 10:27:37 CEST
*** Bug 57470 has been marked as a duplicate of this bug. ***
Comment 4 Julia Bremer univentionstaff 2024-09-04 15:26:15 CEST
OK: bug
OK: yaml
OK: announce_errata
OK: jenkins
OK: piuparts
Verified