QID 198706

Date Published: 2022-03-21

QID 198706: Ubuntu Security Notification for Bind Vulnerabilities (USN-5332-1)

Bindincorrectly handled certain bogus ns records when using forwarders.
Bind incorrectly handled certain crafted tcpstreams.

Aremote attacker could possibly use this issue to manipulate cache results.
A remote attacker could possibly use this issue to cause bind toconsume resources, leading to a denial of service.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5332-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198706

    Software Advisories
    Advisory ID Software Component Link
    USN-5332-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5332-1