CVE-2015-1349

Impact:
Moderate
Public Date:
2015-02-20
CWE:
CWE-391
Bugzilla:
1193820: CVE-2015-1349 bind: issue in trust anchor management can cause named to crash
A flaw was found in the way BIND handled trust anchor management. A remote attacker could use this flaw to cause the BIND daemon (named) to crash under certain conditions.

Find out more about CVE-2015-1349 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat Enterprise Linux 5 ships with both bind (9.3) packages which are not affected by this issue, and bind97 packages, which are affected by this issue.
Red Hat Enterprise Linux 5 is now in Production Phase 3 of the support and maintenance life cycle. This issue is not currently planned to be addressed in future bind97 updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

CVSS v2 metrics

Base Score 2.6
Base Metrics AV:N/AC:H/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (bind) RHSA-2015:0672 2015-03-11
Red Hat Enterprise Linux 6 (bind) RHSA-2015:0672 2015-03-11

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 5 bind97 Will not fix
Red Hat Enterprise Linux 5 bind Not affected

Acknowledgements

Red Hat would like to thank ISC for reporting this issue.

External References

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.