Add release note for [GL #2604]

This commit is contained in:
Michał Kępień
2021-04-29 11:56:03 +02:00
parent 948285ef15
commit 891db84e90
+17
View File
@@ -37,6 +37,23 @@
bringing this vulnerability to our attention. [GL #2540]
</para>
</listitem>
<listitem>
<para>
When a server's configuration set the
<command>tkey-gssapi-keytab</command> or
<command>tkey-gssapi-credential</command> option, a specially crafted
GSS-TSIG query could cause a buffer overflow in the ISC implementation
of SPNEGO (a protocol enabling negotiation of the security mechanism
used for GSSAPI authentication). This flaw could be exploited to crash
<command>named</command> binaries compiled for 64-bit platforms, and
could enable remote code execution when <command>named</command> was
compiled for 32-bit platforms. (CVE-2021-25216)
</para>
<para>
This vulnerability was reported to us as ZDI-CAN-13347 by Trend Micro
Zero Day Initiative. [GL #2604]
</para>
</listitem>
</itemizedlist>
</section>