QID 198348

Date Published: 2021-05-06

QID 198348: Ubuntu Security Notification for Bind vulnerabilities (USN-4929-1)

Bind incorrectly handled gssapi security policy negotiation

A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service
(CVE-2021-25214)
A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service
(CVE-2021-25215)
A remote attacker could use this issue to cause Bind to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2021-25216)

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4929-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198348

    Software Advisories
    Advisory ID Software Component Link
    USN-4929-1 Ubuntu Linux URL Logo usn.ubuntu.com/4929-1