{"affected":[{"ecosystem_specific":{"binaries":[{"bind-utils":"9.16.6-150000.12.77.1","libbind9-1600":"9.16.6-150000.12.77.1","libbind9-1600-64bit":"9.16.6-150000.12.77.1","libdns1605":"9.16.6-150000.12.77.1","libdns1605-64bit":"9.16.6-150000.12.77.1","libirs1601":"9.16.6-150000.12.77.1","libirs1601-64bit":"9.16.6-150000.12.77.1","libisc1606":"9.16.6-150000.12.77.1","libisc1606-64bit":"9.16.6-150000.12.77.1","libisccc1600":"9.16.6-150000.12.77.1","libisccc1600-64bit":"9.16.6-150000.12.77.1","libisccfg1600":"9.16.6-150000.12.77.1","libisccfg1600-64bit":"9.16.6-150000.12.77.1","libns1604":"9.16.6-150000.12.77.1","python3-bind":"9.16.6-150000.12.77.1"}]},"package":{"ecosystem":"SUSE:Manager Client Tools for SLE Micro 5","name":"bind","purl":"pkg:rpm/suse/bind&distro=SUSE%20Manager%20Client%20Tools%20for%20SLE%20Micro%205"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.16.6-150000.12.77.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"bind":"9.16.6-150000.12.77.1","bind-chrootenv":"9.16.6-150000.12.77.1","bind-devel":"9.16.6-150000.12.77.1","bind-doc":"9.16.6-150000.12.77.1","bind-utils":"9.16.6-150000.12.77.1","libbind9-1600":"9.16.6-150000.12.77.1","libdns1605":"9.16.6-150000.12.77.1","libirs-devel":"9.16.6-150000.12.77.1","libirs1601":"9.16.6-150000.12.77.1","libisc1606":"9.16.6-150000.12.77.1","libisccc1600":"9.16.6-150000.12.77.1","libisccfg1600":"9.16.6-150000.12.77.1","libns1604":"9.16.6-150000.12.77.1","python3-bind":"9.16.6-150000.12.77.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS","name":"bind","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.16.6-150000.12.77.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"bind":"9.16.6-150000.12.77.1","bind-chrootenv":"9.16.6-150000.12.77.1","bind-devel":"9.16.6-150000.12.77.1","bind-doc":"9.16.6-150000.12.77.1","bind-utils":"9.16.6-150000.12.77.1","libbind9-1600":"9.16.6-150000.12.77.1","libdns1605":"9.16.6-150000.12.77.1","libirs-devel":"9.16.6-150000.12.77.1","libirs1601":"9.16.6-150000.12.77.1","libisc1606":"9.16.6-150000.12.77.1","libisccc1600":"9.16.6-150000.12.77.1","libisccfg1600":"9.16.6-150000.12.77.1","libns1604":"9.16.6-150000.12.77.1","python3-bind":"9.16.6-150000.12.77.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 15 SP2-LTSS","name":"bind","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.16.6-150000.12.77.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"bind":"9.16.6-150000.12.77.1","bind-chrootenv":"9.16.6-150000.12.77.1","bind-devel":"9.16.6-150000.12.77.1","bind-doc":"9.16.6-150000.12.77.1","bind-utils":"9.16.6-150000.12.77.1","libbind9-1600":"9.16.6-150000.12.77.1","libdns1605":"9.16.6-150000.12.77.1","libirs-devel":"9.16.6-150000.12.77.1","libirs1601":"9.16.6-150000.12.77.1","libisc1606":"9.16.6-150000.12.77.1","libisccc1600":"9.16.6-150000.12.77.1","libisccfg1600":"9.16.6-150000.12.77.1","libns1604":"9.16.6-150000.12.77.1","python3-bind":"9.16.6-150000.12.77.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP2","name":"bind","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.16.6-150000.12.77.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for bind fixes the following issues:\n\n- CVE-2024-1737: It is possible to craft excessively large numbers of\n  resource record types for a given owner name, which has the effect of\n  slowing down database processing. This has been addressed by\n  adding a configurable limit to the number of records that can\n  be stored per name and type in a cache or zone database. The\n  default is 100, which can be tuned with the new\n  max-types-per-name option. (bsc#1228256)\n- CVE-2024-1975: Validating DNS messages signed using the SIG(0)\n  protocol (RFC 2931) could cause excessive CPU load, leading to a\n  denial-of-service condition. Support for SIG(0) message\n  validation was removed from this version of named.\n  (bsc#1228257)\n","id":"SUSE-SU-2024:2811-1","modified":"2024-08-07T07:51:15Z","published":"2024-08-07T07:51:15Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20242811-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228256"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228257"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-1737"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-1975"}],"related":["CVE-2024-1737","CVE-2024-1975"],"summary":"Security update for bind","upstream":["CVE-2024-1737","CVE-2024-1975"]}