Re: CVE-2021-25216

2021-05-03 Thread Petr Menšík
Hello Jordan, Red Hat have been building their BIND packages with --disable-isc-spnego configure parameter for years, all versions still somehow supported by Red Hat are built with them. This means the mentioned issue should not affect Red Hat packages. Please visit [1] to check affected versions.

Re: CVE-2021-25216

2021-04-30 Thread @lbutlr
On 30 Apr 2021, at 08:21, Jordan Tinsley wrote: > Is BIND 9.11.6 (Extended Support Version) vulnerable? > > Is BIND 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.3 (Extended Support Version) > vulnerable? The CVE descriptions indicates both of those versions are vulnerable. "In BIND 9.5.0 -> 9.11.29 … c