Debian Security Advisory
DSA-4857-1 bind9 -- security update
- Date Reported:
- 18 Feb 2021
- Affected Packages:
- bind9
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 983004.
In Mitre's CVE dictionary: CVE-2020-8625. - More information:
-
A buffer overflow vulnerability was discovered in the SPNEGO implementation affecting the GSSAPI security policy negotiation in BIND, a DNS server implementation, which could result in denial of service (daemon crash), or potentially the execution of arbitrary code.
For the stable distribution (buster), this problem has been fixed in version 1:9.11.5.P4+dfsg-5.1+deb10u3.
We recommend that you upgrade your bind9 packages.
For the detailed security status of bind9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/bind9