Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 17 Jun 2020 11:17:17 -0800
From: Michael McNally <mcnally@....org>
To: oss-security@...ts.openwall.com
Subject: ISC announces two medium-severity vulnerabilities, CVE-2020-8618 and
 CVE-2020-8619

ISC has posted the announcement below to our public "bind-announce" list, completing
the disclosure of two medium-severity vulnerabilities, CVE-2020-8618 and CVE-2020-8619.

Package maintainers and distributors who have been holding updated packages in
anticipation of our disclosure are free to proceed now that this information has
been made public.

Thank you to all those who received the information in advance for your cooperation
with our embargo period.

Michael McNally
ISC Security Officer

-----

ISC's June maintenance releases of BIND are available and can be downloaded
from the ISC software download page, https://www.isc.org/download

A summary of changes in the new releases can be found in their release notes:

current supported stable branches:

  9.11.20 - https://downloads.isc.org/isc/bind9/9.11.20/RELEASE-NOTES-bind-9.11.20.html
  9.16.4  - https://downloads.isc.org/isc/bind9/9.16.4/RELEASE-NOTES-bind-9.16.4.html

experimental development branch:

  9.17.2  - https://downloads.isc.org/isc/bind9/9.17.2/RELEASE-NOTES-bind-9.17.2.html

In addition to minor bug fixes and feature improvements, these particular
maintenance releases of BIND also contain fixes for two medium-severity
vulnerabilities, CVE-2020-8618 and CVE-2020-8619, about which more information
is available in these Security Advisories:

  https://kb.isc.org/docs/cve-2020-8618
  https://kb.isc.org/docs/cve-2020-8619

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.