Re: Bind Vulnerability CVE-2016-2775

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Thu, Sep 01, 2016 at 08:34:08AM +0000, James Pearson wrote:
>
> Sidharth Sharma:
> >
> > When we can expect Security Update for Bind Vulnerability on Centos 6.8/7.2?
> > ISC BIND Lightweight Resolver Protocol Req Processing Dos Vulnerability:
>  >CVE-2016-2775
> 
> See:
> 
>  https://access.redhat.com/security/cve/cve-2016-2775

The important takeaway is that Red Hat has marked it as "Will Not
Fix", and in the BZ, the statement is:

"Red Hat Product Security has rated this issue as having Moderate
security impact. This issue is not currently planned to be addressed
in future updates. For additional information, refer to the Issue
Severity Classification:
https://access.redhat.com/security/updates/classification/. 

Note that this issue only affects BIND deployments that make use of
the non-default lightweight resolver protocol for name resolution. "

-- 
Jonathan Billings <billings@xxxxxxxxxx>
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
https://lists.centos.org/mailman/listinfo/centos



[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux