https://seclists.org/oss-sec/2023/q3/197: ISC has disclosed two vulnerabilities in BIND 9 (CVE-2023-3341, CVE-2023-4236)
Published Sep 20, 2023
·Updated
Affected Software
1 affected component
Internet Systems Consortium BIND 9>=9.16.44, >=9.18.19, >=9.19.17
Frequently Asked Questions
1
What is the severity of CVE-2023-3341?
CVE-2023-3341 has been classified as a high severity vulnerability due to its potential to cause named to terminate unexpectedly.
2
How do I fix CVE-2023-3341?
To address CVE-2023-3341, users should update to the latest version of BIND 9 provided by Internet Systems Consortium.
3
What systems are affected by CVE-2023-4236?
CVE-2023-4236 affects installations of BIND 9 that use its control channel feature.
4
What are the potential impacts of CVE-2023-4236?
CVE-2023-4236 may result in named terminating unexpectedly, leading to a denial of service.
5
When was CVE-2023-3341 disclosed?
CVE-2023-3341 was disclosed on September 20, 2023, by Internet Systems Consortium.