The vendor explicitly identifies these products as affected by this CVE.
- bind as a component of Red Hat Enterprise Linux 6
- bind-chroot as a component of Red Hat Enterprise Linux 6
- bind-devel as a component of Red Hat Enterprise Linux 6
- bind-libs as a component of Red Hat Enterprise Linux 6
- bind-sdb as a component of Red Hat Enterprise Linux 6
- bind-utils as a component of Red Hat Enterprise Linux 6
- bind.src as a component of Red Hat Enterprise Linux 6
- Summary
- An assertion failure was found in the way bind implemented the "managed keys" feature. An attacker could use this flaw to cause the named daemon to crash. This flaw is very difficult for an attacker to trigger because it requires an operator to have BIND configured to use a trust anchor managed by the attacker.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, the BIND daemon (named) will be restarted automatically.
