oss-sec mailing list archives
ISC announces two medium-severity vulnerabilities, CVE-2020-8618 and CVE-2020-8619
From: Michael McNally <mcnally () isc org>
Date: Wed, 17 Jun 2020 11:17:17 -0800
ISC has posted the announcement below to our public "bind-announce" list, completing the disclosure of two medium-severity vulnerabilities, CVE-2020-8618 and CVE-2020-8619. Package maintainers and distributors who have been holding updated packages in anticipation of our disclosure are free to proceed now that this information has been made public. Thank you to all those who received the information in advance for your cooperation with our embargo period. Michael McNally ISC Security Officer ----- ISC's June maintenance releases of BIND are available and can be downloaded from the ISC software download page, https://www.isc.org/download A summary of changes in the new releases can be found in their release notes: current supported stable branches: 9.11.20 - https://downloads.isc.org/isc/bind9/9.11.20/RELEASE-NOTES-bind-9.11.20.html 9.16.4 - https://downloads.isc.org/isc/bind9/9.16.4/RELEASE-NOTES-bind-9.16.4.html experimental development branch: 9.17.2 - https://downloads.isc.org/isc/bind9/9.17.2/RELEASE-NOTES-bind-9.17.2.html In addition to minor bug fixes and feature improvements, these particular maintenance releases of BIND also contain fixes for two medium-severity vulnerabilities, CVE-2020-8618 and CVE-2020-8619, about which more information is available in these Security Advisories: https://kb.isc.org/docs/cve-2020-8618 https://kb.isc.org/docs/cve-2020-8619
Current thread:
- ISC announces two medium-severity vulnerabilities, CVE-2020-8618 and CVE-2020-8619 Michael McNally (Jun 17)