{"affected":[{"ecosystem_specific":{"binaries":[{"bind":"9.9.9P1-28.42.1","bind-chrootenv":"9.9.9P1-28.42.1","bind-devel":"9.9.9P1-28.42.1","bind-doc":"9.9.9P1-28.42.1","bind-libs":"9.9.9P1-28.42.1","bind-libs-32bit":"9.9.9P1-28.42.1","bind-utils":"9.9.9P1-28.42.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"bind","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.9.9P1-28.42.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for bind fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2018-5740: Fixed a denial of service vulnerability in the 'deny-answer-aliases' feature (bsc#1104129).\n- CVE-2019-6465: Fixed an issue where controls for zone transfers may not be properly applied to Dynamically Loadable Zones (bsc#1126069).\n- CVE-2018-5745: An assertion failure can occur if a trust anchor rolls over to an unsupported key algorithm when using managed-keys. (bsc#1126068)\n- CVE-2018-5743: Limiting simultaneous TCP clients is ineffective. (bsc#1133185)\n\n","id":"SUSE-SU-2019:1449-1","modified":"2019-06-07T11:00:10Z","published":"2019-06-07T11:00:10Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20191449-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1104129"},{"type":"REPORT","url":"https://bugzilla.suse.com/1126068"},{"type":"REPORT","url":"https://bugzilla.suse.com/1126069"},{"type":"REPORT","url":"https://bugzilla.suse.com/1133185"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5740"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5743"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5745"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6465"}],"related":["CVE-2018-5740","CVE-2018-5743","CVE-2018-5745","CVE-2019-6465"],"summary":"Security update for bind","upstream":["CVE-2018-5740","CVE-2018-5743","CVE-2018-5745","CVE-2019-6465"]}