[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] ISC announces two medium-severity vulnerabilities, CVE-2020-8618 and CVE-2020-8619
From:       Michael McNally <mcnally () isc ! org>
Date:       2020-06-17 19:17:17
Message-ID: a642507a-b5d4-3108-6505-75beb1795b66 () isc ! org
[Download RAW message or body]

ISC has posted the announcement below to our public "bind-announce" list, completing
the disclosure of two medium-severity vulnerabilities, CVE-2020-8618 and CVE-2020-8619.

Package maintainers and distributors who have been holding updated packages in
anticipation of our disclosure are free to proceed now that this information has
been made public.

Thank you to all those who received the information in advance for your cooperation
with our embargo period.

Michael McNally
ISC Security Officer

-----

ISC's June maintenance releases of BIND are available and can be downloaded
from the ISC software download page, https://www.isc.org/download

A summary of changes in the new releases can be found in their release notes:

current supported stable branches:

  9.11.20 - https://downloads.isc.org/isc/bind9/9.11.20/RELEASE-NOTES-bind-9.11.20.html
  9.16.4  - https://downloads.isc.org/isc/bind9/9.16.4/RELEASE-NOTES-bind-9.16.4.html

experimental development branch:

  9.17.2  - https://downloads.isc.org/isc/bind9/9.17.2/RELEASE-NOTES-bind-9.17.2.html

In addition to minor bug fixes and feature improvements, these particular
maintenance releases of BIND also contain fixes for two medium-severity
vulnerabilities, CVE-2020-8618 and CVE-2020-8619, about which more information
is available in these Security Advisories:

  https://kb.isc.org/docs/cve-2020-8618
  https://kb.isc.org/docs/cve-2020-8619
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic