USN-4468-2: Bind vulnerability
USN-4468-1 fixed a vulnerability in Bind. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: Dave Feldman, Jeff Warren, and Joel Cunningham discovered that Bind incorrectly handled certain truncated responses to a TSIG-signed request. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. (CVE-2020-8622)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Bind vulnerability?
The vulnerability ID of this Bind vulnerability is USN-4468-2.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Ubuntu 12.04 ESM and Ubuntu 14.04 ESM with Bind 9.8.1.dfsg.P1-4ubuntu0.31 and Bind 9.9.5.dfsg-3ubuntu0.19+esm3 respectively.
What is the description of this vulnerability?
This vulnerability in Bind incorrectly handles certain truncated responses to a TSIG-signed request.
What is the severity of the Bind vulnerability?
The severity of the Bind vulnerability is not specified in the provided information.
How do I fix the Bind vulnerability?
To fix the Bind vulnerability, update to the latest version of Bind provided in the associated security advisories (USN-4468-1).