cve-2015-5722 AND cve-2015-5986

Support for security such as Firewalls and securing linux
Post Reply

User avatar
TrevorH
Site Admin
Posts: 33218
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: cve-2015-5722 AND cve-2015-5986

Post by TrevorH » 2015/09/03 09:49:44

If RH has built them and released them via RHSA announcements then they will be rebuilt by CentOS and released in due course. The packages you're looking at were only released by RH at 04:00 this morning.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

moranwang
Posts: 1
Joined: 2015/09/07 08:47:42

Re: cve-2015-5722 AND cve-2015-5986

Post by moranwang » 2015/09/07 08:53:54

hello,
is the bind fix CVE-2015-5986 released now? in fast track?

thanks alot.

User avatar
avij
Retired Moderator
Posts: 3046
Joined: 2010/12/01 19:25:52
Location: Helsinki, Finland
Contact:

Re: cve-2015-5722 AND cve-2015-5986

Post by avij » 2015/09/07 09:53:57

Code: Select all

# rpm -q bind --changelog | grep -e CVE-2015-5722 -e CVE-2015-5986
- Apply previously not applied patch for CVE-2015-5722
- Fix CVE-2015-5722
# rpm -q bind
bind-9.8.2-0.37.rc1.el6_7.4.x86_64
The fixed packages were published on the same day as Red Hat published their update, ie. Thursday last week. You can get the update via the normal updates repository with a simple yum update.

As for CVE-2015-5986, the bind packages as shipped by Red Hat and CentOS are not vulnerable and thus do not need patching for this flaw.

No, important security updates are unlikely to be published in the fasttrack repository. Please read the upstream description of the channel.

Post Reply