BIND 9 CVE's Posted

Status
Not open for further replies.

UCMUserAZ

Customer
Joined
Dec 19, 2023
Messages
124
Reaction score
215
Hi there. I am sure 3cx is on top of this, but just noting Bind 9 version 9.18.24, we were told by our Security CVE's just came out for it yesterday. Shows it is fixed in 9.18.28. Would 3cx be looking at this for next month release or due to the severity it would come sooner? Just want to update our Security team with the process. Will await 3cx workaround or official stance. Thanks in advance.

CVE-2024-4076
CVE-2024-1975
CVE-2024-1737
CVE-2024-0760
 
Hi,

Our repository currently holds the following bind9 related packages
  • bind9-dnsutils
  • bind9-host
  • bind9-libs
Having said, Debian hasn't released any update for those vulnerabilities:

BugbullseyebookwormDescription
CVE-2024-4076vulnerablevulnerableClient queries that trigger serving stale data and that also require l ...
CVE-2024-1975vulnerablevulnerableIf a server hosts a zone containing a "KEY" Resource Record, or a reso ...
CVE-2024-1737vulnerablevulnerableResolver caches and authoritative zone databases that hold significant ...
CVE-2024-0760vulnerablevulnerableA malicious client can send many DNS messages over TCP, potentially ca ...
 
Hi,

Our repository currently holds the following bind9 related packages
  • bind9-dnsutils
  • bind9-host
  • bind9-libs
Having said, Debian hasn't released any update for those vulnerabilities:

BugbullseyebookwormDescription
CVE-2024-4076vulnerablevulnerableClient queries that trigger serving stale data and that also require l ...
CVE-2024-1975vulnerablevulnerableIf a server hosts a zone containing a "KEY" Resource Record, or a reso ...
CVE-2024-1737vulnerablevulnerableResolver caches and authoritative zone databases that hold significant ...
CVE-2024-0760vulnerablevulnerableA malicious client can send many DNS messages over TCP, potentially ca ...
Thank you. Will let our security know 3cx is aware and there are no stable fixes yet. Thanks for quick reply.
 
Hi,

Our repository currently holds the following bind9 related packages
  • bind9-dnsutils
  • bind9-host
  • bind9-libs
Having said, Debian hasn't released any update for those vulnerabilities:

BugbullseyebookwormDescription
CVE-2024-4076vulnerablevulnerableClient queries that trigger serving stale data and that also require l ...
CVE-2024-1975vulnerablevulnerableIf a server hosts a zone containing a "KEY" Resource Record, or a reso ...
CVE-2024-1737vulnerablevulnerableResolver caches and authoritative zone databases that hold significant ...
CVE-2024-0760vulnerablevulnerableA malicious client can send many DNS messages over TCP, potentially ca ...
Hi Agathocles,

I see they fixed the above in Bookworm (security) release 1:9.18.28-1~deb12u2. Does 3cx test/install these "security" designated fixes of Debian or do you wait for the standard Bookworm fix release? Thanks in advance.
 
Hi @UCMUserAZ ,

Yes, we do test updates from the security repository as well as the main.

I can confirm 1:9.18.28-1~deb12u2 is in our internal repo and queued for testing. I can't give an exact date though for the release.
 
  • Like
Reactions: UCMUserAZ
Hi @UCMUserAZ ,

Yes, we do test updates from the security repository as well as the main.

I can confirm 1:9.18.28-1~deb12u2 is in our internal repo and queued for testing. I can't give an exact date though for the release.
Hi Agathocles,
Just checking on the Bind9 patches. Our Security was just asking and I said I would check to see if when we can expect this if you have? Thanks again.
 
Hi Agathocles,
Just checking on the Bind9 patches. Our Security was just asking and I said I would check to see if when we can expect this if you have? Thanks again.
Hi there,

We're considering releasing a batch of security updates next week but its not certain yet.

I will let you know.
 
Hi there,

We're considering releasing a batch of security updates next week but its not certain yet.

I will let you know.
Will this be in the Update 3 release? Thanks in advance.
 
Will this be in the Update 3 release? Thanks in advance.
Hi,

The packages in question have been uploaded to the U3 repository today. The rest of the repos will follow later.
 
  • Like
Reactions: UCMUserAZ and NCIA
Hi,

The packages in question have been uploaded to the U3 repository today. The rest of the repos will follow later.
Thank you. I see them. Installing this morning. Thanks for the update.
 
Status
Not open for further replies.

Forum statistics

Threads
111,954
Messages
589,921
Members
164,851
Latest member
DrunkeMeister