Oval Definition:oval:org.opensuse.security:def:202125216
Revision Date:2023-06-22Version:1
Title:CVE-2021-25216
Description:

In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-25216
SUSE CVE-2021-25216
SUSE-SU-2021:1469-1
SUSE-SU-2021:14714-1
Platform(s):openSUSE Leap 15.4
openSUSE Tumbleweed
SUSE Linux Enterprise Desktop 15 SP3
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise High Performance Computing 15 SP4
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Basesystem 15 SP3
SUSE Linux Enterprise Module for Basesystem 15 SP4
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Module for Server Applications 15 SP3
SUSE Linux Enterprise Module for Server Applications 15 SP4
SUSE Linux Enterprise Server 11 SP1-TERADATA
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server 11 SP4-LTSS
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP5
SUSE Linux Enterprise Storage 7.1
SUSE Manager Proxy 4.2
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.2
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.2
SUSE Manager Server 4.3
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • bind-9.9.9P1-63.25.1 is installed
  • OR bind-chrootenv-9.9.9P1-63.25.1 is installed
  • OR bind-doc-9.9.9P1-63.25.1 is installed
  • OR bind-libs-9.9.9P1-63.25.1 is installed
  • OR bind-libs-32bit-9.9.9P1-63.25.1 is installed
  • OR bind-utils-9.9.9P1-63.25.1 is installed
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • bind-9.16.20-1.4 is installed
  • OR bind-doc-9.16.20-1.4 is installed
  • OR bind-utils-9.16.20-1.4 is installed
  • OR python3-bind-9.16.20-1.4 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP3 is installed
  • AND
  • bind-9.9.9P1-63.25.1 is installed
  • OR bind-chrootenv-9.9.9P1-63.25.1 is installed
  • OR bind-doc-9.9.9P1-63.25.1 is installed
  • OR bind-libs-9.9.9P1-63.25.1 is installed
  • OR bind-libs-32bit-9.9.9P1-63.25.1 is installed
  • OR bind-utils-9.9.9P1-63.25.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • OR SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • OR SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND
  • bind-9.9.9P1-63.25.1 is installed
  • OR bind-chrootenv-9.9.9P1-63.25.1 is installed
  • OR bind-doc-9.9.9P1-63.25.1 is installed
  • OR bind-libs-9.9.9P1-63.25.1 is installed
  • OR bind-libs-32bit-9.9.9P1-63.25.1 is installed
  • OR bind-utils-9.9.9P1-63.25.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND
  • bind-9.9.9P1-63.25.1 is installed
  • OR bind-chrootenv-9.9.9P1-63.25.1 is installed
  • OR bind-doc-9.9.9P1-63.25.1 is installed
  • OR bind-libs-9.9.9P1-63.25.1 is installed
  • OR bind-libs-32bit-9.9.9P1-63.25.1 is installed
  • OR bind-utils-9.9.9P1-63.25.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND
  • bind-9.9.9P1-63.25.1 is installed
  • OR bind-chrootenv-9.9.9P1-63.25.1 is installed
  • OR bind-doc-9.9.9P1-63.25.1 is installed
  • OR bind-libs-9.9.9P1-63.25.1 is installed
  • OR bind-libs-32bit-9.9.9P1-63.25.1 is installed
  • OR bind-utils-9.9.9P1-63.25.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
  • OR SUSE Linux Enterprise Module for Server Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Server 15 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Storage 7.1 is installed
  • OR SUSE Manager Proxy 4.2 is installed
  • OR SUSE Manager Retail Branch Server 4.2 is installed
  • OR SUSE Manager Server 4.2 is installed
  • AND
  • bind is affected
  • OR bind-chrootenv is affected
  • OR bind-doc is affected
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP3 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
  • OR SUSE Linux Enterprise Server 15 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Storage 7.1 is installed
  • OR SUSE Manager Proxy 4.2 is installed
  • OR SUSE Manager Retail Branch Server 4.2 is installed
  • OR SUSE Manager Server 4.2 is installed
  • AND
  • bind-devel is affected
  • OR bind-utils is affected
  • OR libbind9-1600 is affected
  • OR libdns1605 is affected
  • OR libirs-devel is affected
  • OR libirs1601 is affected
  • OR libisc1606 is affected
  • OR libisccc1600 is affected
  • OR libisccfg1600 is affected
  • OR libns1604 is affected
  • OR python3-bind is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP3 is installed
  • OR SUSE Linux Enterprise Desktop 15 SP4 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP3 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Linux Enterprise Storage 7.1 is installed
  • OR SUSE Manager Proxy 4.2 is installed
  • OR SUSE Manager Proxy 4.3 is installed
  • OR SUSE Manager Retail Branch Server 4.2 is installed
  • OR SUSE Manager Retail Branch Server 4.3 is installed
  • OR SUSE Manager Server 4.2 is installed
  • OR SUSE Manager Server 4.3 is installed
  • AND Package Information
  • bind-devel is affected
  • OR bind-utils is affected
  • OR libbind9-1600 is affected
  • OR libdns1605 is affected
  • OR libirs-devel is affected
  • OR libirs1601 is affected
  • OR libisc1606 is affected
  • OR libisccc1600 is affected
  • OR libisccfg1600 is affected
  • OR libns1604 is affected
  • OR python3-bind is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • AND
  • bind-9.6ESVR11W1-0.31.21.1 is installed
  • OR bind-chrootenv-9.6ESVR11W1-0.31.21.1 is installed
  • OR bind-doc-9.6ESVR11W1-0.31.21.1 is installed
  • OR bind-libs-9.6ESVR11W1-0.31.21.1 is installed
  • OR bind-libs-32bit-9.6ESVR11W1-0.31.21.1 is installed
  • OR bind-utils-9.6ESVR11W1-0.31.21.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • AND
  • bind-9.9.6P1-0.51.26.1 is installed
  • OR bind-chrootenv-9.9.6P1-0.51.26.1 is installed
  • OR bind-doc-9.9.6P1-0.51.26.1 is installed
  • OR bind-libs-9.9.6P1-0.51.26.1 is installed
  • OR bind-libs-32bit-9.9.6P1-0.51.26.1 is installed
  • OR bind-utils-9.9.6P1-0.51.26.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • AND
  • bind-9.9.6P1-0.51.26.1 is installed
  • OR bind-chrootenv-9.9.6P1-0.51.26.1 is installed
  • OR bind-doc-9.9.6P1-0.51.26.1 is installed
  • OR bind-libs-9.9.6P1-0.51.26.1 is installed
  • OR bind-libs-32bit-9.9.6P1-0.51.26.1 is installed
  • OR bind-utils-9.9.6P1-0.51.26.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • OR SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • OR SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND
  • bind-9.9.9P1-63.25.1 is installed
  • OR bind-chrootenv-9.9.9P1-63.25.1 is installed
  • OR bind-doc-9.9.9P1-63.25.1 is installed
  • OR bind-libs-9.9.9P1-63.25.1 is installed
  • OR bind-libs-32bit-9.9.9P1-63.25.1 is installed
  • OR bind-utils-9.9.9P1-63.25.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND
  • bind-9.9.9P1-63.25.1 is installed
  • OR bind-chrootenv-9.9.9P1-63.25.1 is installed
  • OR bind-doc-9.9.9P1-63.25.1 is installed
  • OR bind-libs-9.9.9P1-63.25.1 is installed
  • OR bind-libs-32bit-9.9.9P1-63.25.1 is installed
  • OR bind-utils-9.9.9P1-63.25.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND
  • bind-9.9.9P1-63.25.1 is installed
  • OR bind-chrootenv-9.9.9P1-63.25.1 is installed
  • OR bind-doc-9.9.9P1-63.25.1 is installed
  • OR bind-libs-9.9.9P1-63.25.1 is installed
  • OR bind-libs-32bit-9.9.9P1-63.25.1 is installed
  • OR bind-utils-9.9.9P1-63.25.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • bind-9.16.20-150400.3.6 is installed
  • AND bind is signed with openSUSE key
  • OR
  • bind-utils-9.16.20-150400.3.6 is installed
  • AND bind-utils is signed with openSUSE key
  • OR
  • python3-bind-9.16.20-150400.3.6 is installed
  • AND python3-bind is signed with openSUSE key
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP4 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Manager Proxy 4.3 is installed
  • OR SUSE Manager Retail Branch Server 4.3 is installed
  • OR SUSE Manager Server 4.3 is installed
  • AND
  • bind-devel-9.16.6-150300.22.16.1 is installed
  • OR bind-utils-9.16.20-150400.3.6 is installed
  • OR libbind9-1600-9.16.6-150300.22.16.1 is installed
  • OR libdns1605-9.16.6-150300.22.16.1 is installed
  • OR libirs-devel-9.16.6-150300.22.16.1 is installed
  • OR libirs1601-9.16.6-150300.22.16.1 is installed
  • OR libisc1606-9.16.6-150300.22.16.1 is installed
  • OR libisccc1600-9.16.6-150300.22.16.1 is installed
  • OR libisccfg1600-9.16.6-150300.22.16.1 is installed
  • OR libns1604-9.16.6-150300.22.16.1 is installed
  • OR python3-bind-9.16.20-150400.3.6 is installed
  • OR Package Information
  • SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Module for Server Applications 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Manager Proxy 4.3 is installed
  • OR SUSE Manager Retail Branch Server 4.3 is installed
  • OR SUSE Manager Server 4.3 is installed
  • AND
  • bind-9.16.20-150400.3.6 is installed
  • OR bind-doc-9.16.20-150400.3.6 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • bind-devel-9.16.6-150300.22.27.1 is installed
  • OR bind-utils-9.16.38-150400.5.20.2 is installed
  • OR libbind9-1600-9.16.6-150300.22.27.1 is installed
  • OR libdns1605-9.16.6-150300.22.27.1 is installed
  • OR libirs-devel-9.16.6-150300.22.27.1 is installed
  • OR libirs1601-9.16.6-150300.22.27.1 is installed
  • OR libisc1606-9.16.6-150300.22.27.1 is installed
  • OR libisccc1600-9.16.6-150300.22.27.1 is installed
  • OR libisccfg1600-9.16.6-150300.22.27.1 is installed
  • OR libns1604-9.16.6-150300.22.27.1 is installed
  • OR python3-bind-9.16.38-150400.5.20.2 is installed
  • BACK