OracleVM 3.3 / 3.4 : bind (OVMSA-2018-0252)

High Nessus Plugin ID 112170


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- Fix (CVE-2018-5740)

- Fix (CVE-2017-3145)

- Change EDNS flags only after successful query (#1416035)

- Fix crash in ldap driver at bind-sdb stop (#1426626)

- Fix (CVE-2017-3142, CVE-2017-3143)

- Update root servers and trust anchors

- Fix DNSKEY that encountered a CNAME (#1447872, ISC change 3391)

- Fix CVE-2017-3136 (ISC change 4575)

- Fix CVE-2017-3137 (ISC change 4578)


Update the affected bind-libs / bind-utils packages.

See Also

Plugin Details

Severity: High

ID: 112170

File Name: oraclevm_OVMSA-2018-0252.nasl

Version: 1.1

Type: local

Published: 2018/08/29

Modified: 2018/08/29

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:bind-libs, p-cpe:/a:oracle:vm:bind-utils, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Patch Publication Date: 2018/08/27

Reference Information

CVE: CVE-2017-3136, CVE-2017-3137, CVE-2017-3142, CVE-2017-3143, CVE-2017-3145, CVE-2018-5740