| Summary: | bind: CVE-2016-2088 (jethro) | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Jussi Kukkonen <jku> |
| Component: | connectivity | Assignee: | Jussi Kukkonen <jku> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | major | ||
| Priority: | Medium | CC: | akuster, meta.mr.watcher, meta.watcher, randy.macleod, sona.sarmadi |
| Version: | 2.0 | ||
| Target Milestone: | 2.0.3 | ||
| Hardware: | All | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
| Bug Depends on: | 9438 | ||
| Bug Blocks: | |||
|
Description
Jussi Kukkonen
2016-04-18 12:30:37 UTC
It's worth noting that bind as built with the oe-core recipe is not really at risk: Only servers which are built with DNS cookie support (--enable-sit) are vulnerable to denial of service. jethro patch sent. |