oss-sec mailing list archives

ISC has disclosed two vulnerabilities in BIND 9.12 (CVE-2018-5736, CVE-2018-5737)


From: ISC Security Officer <security-officer () isc org>
Date: Fri, 18 May 2018 14:08:27 -0800

ISC has disclosed two vulnerabilities today, CVE-2018-5736
and CVE-2018-5736.  Both vulnerabilities affect only releases
in the BIND 9.12 branch (that is:  9.12.0 and 9.12.1.)
Releases in other branches (such as 9.9, 9.10, 9.11) are not affected.

To address these issues a new security release of BIND, 9.12.1-P2,
has been issued.

BIND 9.12.1-P2 can be found via the ISC software download page:

   https://www.isc.org/downloads

Advisories with details about the two vulnerabilities are
now published in the ISC Knowledge base at:

   https://kb.isc.org/article/AA-01602/74/CVE-2018-5736
   https://kb.isc.org/article/AA-01606/74/CVE-2018-5737

Michael McNally
ISC Security Officer


Current thread: