File _patchinfo of Package patchinfo.2163

<patchinfo incident="2163">
  <issue id="970073" tracker="bnc">VUL-0: EMBARGOED: CVE-2016-1286: bind: An error when parsing signature records for DNAME can lead to named exiting due to an assertion  failure</issue>
  <issue id="970072" tracker="bnc">VUL-0: EMBARGOED: CVE-2016-1285: bind: assert failure on input parsing can cause premature exit</issue>
  <issue id="CVE-2016-1286" tracker="cve" />
  <issue id="CVE-2016-1285" tracker="cve" />
  <category>security</category>
  <rating>important</rating>
  <packager>rmax</packager>
  <description>
This update for bind fixes the following issues:

Fix two assertion failures that can lead to a remote denial of service attack:
* CVE-2016-1285: An error when parsing signature records for DNAME can lead to named exiting due to an assertion failure. (bsc#970072)
* CVE-2016-1286: An error when parsing signature records for DNAME records having specific properties can lead to named exiting due to an assertion failure in resolver.c or db.c. (bsc#970073)
</description>
  <summary>Security update for bind</summary>
</patchinfo>
openSUSE Build Service is sponsored by