<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">bind-9.10.3P4-21.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:10467</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-17T21:45:33Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-17T21:45:33Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-17T21:45:33Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">bind-9.10.3P4-21.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the bind-9.10.3P4-21.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-10467</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL/>
      <Description>E-Mail link for openSUSE-SU-2024:10467</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2009-0696/</URL>
      <Description>SUSE CVE CVE-2009-0696 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2009-4022/</URL>
      <Description>SUSE CVE CVE-2009-4022 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3613/</URL>
      <Description>SUSE CVE CVE-2010-3613 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3614/</URL>
      <Description>SUSE CVE CVE-2010-3614 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3615/</URL>
      <Description>SUSE CVE CVE-2010-3615 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-0414/</URL>
      <Description>SUSE CVE CVE-2011-0414 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-1907/</URL>
      <Description>SUSE CVE CVE-2011-1907 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-1910/</URL>
      <Description>SUSE CVE CVE-2011-1910 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-2464/</URL>
      <Description>SUSE CVE CVE-2011-2464 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-4313/</URL>
      <Description>SUSE CVE CVE-2011-4313 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-1667/</URL>
      <Description>SUSE CVE CVE-2012-1667 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-3817/</URL>
      <Description>SUSE CVE CVE-2012-3817 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-3868/</URL>
      <Description>SUSE CVE CVE-2012-3868 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-4244/</URL>
      <Description>SUSE CVE CVE-2012-4244 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-5166/</URL>
      <Description>SUSE CVE CVE-2012-5166 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-5688/</URL>
      <Description>SUSE CVE CVE-2012-5688 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-5689/</URL>
      <Description>SUSE CVE CVE-2012-5689 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-2266/</URL>
      <Description>SUSE CVE CVE-2013-2266 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4854/</URL>
      <Description>SUSE CVE CVE-2013-4854 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0591/</URL>
      <Description>SUSE CVE CVE-2014-0591 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3214/</URL>
      <Description>SUSE CVE CVE-2014-3214 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3859/</URL>
      <Description>SUSE CVE CVE-2014-3859 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-8500/</URL>
      <Description>SUSE CVE CVE-2014-8500 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-8680/</URL>
      <Description>SUSE CVE CVE-2014-8680 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-1349/</URL>
      <Description>SUSE CVE CVE-2015-1349 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-4620/</URL>
      <Description>SUSE CVE CVE-2015-4620 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-5477/</URL>
      <Description>SUSE CVE CVE-2015-5477 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-5722/</URL>
      <Description>SUSE CVE CVE-2015-5722 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-5986/</URL>
      <Description>SUSE CVE CVE-2015-5986 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8000/</URL>
      <Description>SUSE CVE CVE-2015-8000 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8704/</URL>
      <Description>SUSE CVE CVE-2015-8704 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8705/</URL>
      <Description>SUSE CVE CVE-2015-8705 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1285/</URL>
      <Description>SUSE CVE CVE-2016-1285 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1286/</URL>
      <Description>SUSE CVE CVE-2016-1286 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2088/</URL>
      <Description>SUSE CVE CVE-2016-2088 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2776/</URL>
      <Description>SUSE CVE CVE-2016-2776 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-8864/</URL>
      <Description>SUSE CVE CVE-2016-8864 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="bind-9.10.3P4-21.1">
      <FullProductName ProductID="bind-9.10.3P4-21.1">bind-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="bind-chrootenv-9.10.3P4-21.1">
      <FullProductName ProductID="bind-chrootenv-9.10.3P4-21.1">bind-chrootenv-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="bind-devel-9.10.3P4-21.1">
      <FullProductName ProductID="bind-devel-9.10.3P4-21.1">bind-devel-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="bind-devel-32bit-9.10.3P4-21.1">
      <FullProductName ProductID="bind-devel-32bit-9.10.3P4-21.1">bind-devel-32bit-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="bind-doc-9.10.3P4-21.1">
      <FullProductName ProductID="bind-doc-9.10.3P4-21.1">bind-doc-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="bind-lwresd-9.10.3P4-21.1">
      <FullProductName ProductID="bind-lwresd-9.10.3P4-21.1">bind-lwresd-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="bind-utils-9.10.3P4-21.1">
      <FullProductName ProductID="bind-utils-9.10.3P4-21.1">bind-utils-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="idnkit-1.0-21.1">
      <FullProductName ProductID="idnkit-1.0-21.1">idnkit-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="idnkit-devel-1.0-21.1">
      <FullProductName ProductID="idnkit-devel-1.0-21.1">idnkit-devel-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="idnkit-devel-32bit-1.0-21.1">
      <FullProductName ProductID="idnkit-devel-32bit-1.0-21.1">idnkit-devel-32bit-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libbind9-140-9.10.3P4-21.1">
      <FullProductName ProductID="libbind9-140-9.10.3P4-21.1">libbind9-140-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libbind9-140-32bit-9.10.3P4-21.1">
      <FullProductName ProductID="libbind9-140-32bit-9.10.3P4-21.1">libbind9-140-32bit-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdns162-9.10.3P4-21.1">
      <FullProductName ProductID="libdns162-9.10.3P4-21.1">libdns162-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdns162-32bit-9.10.3P4-21.1">
      <FullProductName ProductID="libdns162-32bit-9.10.3P4-21.1">libdns162-32bit-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libidnkit1-1.0-21.1">
      <FullProductName ProductID="libidnkit1-1.0-21.1">libidnkit1-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libidnkit1-32bit-1.0-21.1">
      <FullProductName ProductID="libidnkit1-32bit-1.0-21.1">libidnkit1-32bit-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libidnkitlite1-1.0-21.1">
      <FullProductName ProductID="libidnkitlite1-1.0-21.1">libidnkitlite1-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libidnkitlite1-32bit-1.0-21.1">
      <FullProductName ProductID="libidnkitlite1-32bit-1.0-21.1">libidnkitlite1-32bit-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libidnkitres1-1.0-21.1">
      <FullProductName ProductID="libidnkitres1-1.0-21.1">libidnkitres1-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libidnkitres1-32bit-1.0-21.1">
      <FullProductName ProductID="libidnkitres1-32bit-1.0-21.1">libidnkitres1-32bit-1.0-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libirs-devel-9.10.3P4-21.1">
      <FullProductName ProductID="libirs-devel-9.10.3P4-21.1">libirs-devel-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libirs141-9.10.3P4-21.1">
      <FullProductName ProductID="libirs141-9.10.3P4-21.1">libirs141-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libirs141-32bit-9.10.3P4-21.1">
      <FullProductName ProductID="libirs141-32bit-9.10.3P4-21.1">libirs141-32bit-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libisc160-9.10.3P4-21.1">
      <FullProductName ProductID="libisc160-9.10.3P4-21.1">libisc160-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libisc160-32bit-9.10.3P4-21.1">
      <FullProductName ProductID="libisc160-32bit-9.10.3P4-21.1">libisc160-32bit-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libisccc140-9.10.3P4-21.1">
      <FullProductName ProductID="libisccc140-9.10.3P4-21.1">libisccc140-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libisccc140-32bit-9.10.3P4-21.1">
      <FullProductName ProductID="libisccc140-32bit-9.10.3P4-21.1">libisccc140-32bit-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libisccfg140-9.10.3P4-21.1">
      <FullProductName ProductID="libisccfg140-9.10.3P4-21.1">libisccfg140-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libisccfg140-32bit-9.10.3P4-21.1">
      <FullProductName ProductID="libisccfg140-32bit-9.10.3P4-21.1">libisccfg140-32bit-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="liblwres141-9.10.3P4-21.1">
      <FullProductName ProductID="liblwres141-9.10.3P4-21.1">liblwres141-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="liblwres141-32bit-9.10.3P4-21.1">
      <FullProductName ProductID="liblwres141-32bit-9.10.3P4-21.1">liblwres141-32bit-9.10.3P4-21.1</FullProductName>
    </Branch>
    <Relationship ProductReference="bind-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:bind-9.10.3P4-21.1">bind-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="bind-chrootenv-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1">bind-chrootenv-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="bind-devel-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1">bind-devel-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="bind-devel-32bit-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1">bind-devel-32bit-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="bind-doc-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1">bind-doc-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="bind-lwresd-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1">bind-lwresd-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="bind-utils-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1">bind-utils-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="idnkit-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:idnkit-1.0-21.1">idnkit-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="idnkit-devel-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:idnkit-devel-1.0-21.1">idnkit-devel-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="idnkit-devel-32bit-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1">idnkit-devel-32bit-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libbind9-140-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1">libbind9-140-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libbind9-140-32bit-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1">libbind9-140-32bit-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libdns162-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libdns162-9.10.3P4-21.1">libdns162-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libdns162-32bit-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1">libdns162-32bit-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libidnkit1-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libidnkit1-1.0-21.1">libidnkit1-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libidnkit1-32bit-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1">libidnkit1-32bit-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libidnkitlite1-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libidnkitlite1-1.0-21.1">libidnkitlite1-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libidnkitlite1-32bit-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1">libidnkitlite1-32bit-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libidnkitres1-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libidnkitres1-1.0-21.1">libidnkitres1-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libidnkitres1-32bit-1.0-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1">libidnkitres1-32bit-1.0-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libirs-devel-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1">libirs-devel-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libirs141-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libirs141-9.10.3P4-21.1">libirs141-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libirs141-32bit-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1">libirs141-32bit-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libisc160-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libisc160-9.10.3P4-21.1">libisc160-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libisc160-32bit-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1">libisc160-32bit-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libisccc140-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1">libisccc140-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libisccc140-32bit-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1">libisccc140-32bit-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libisccfg140-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1">libisccfg140-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libisccfg140-32bit-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1">libisccfg140-32bit-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="liblwres141-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1">liblwres141-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="liblwres141-32bit-9.10.3P4-21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1">liblwres141-32bit-9.10.3P4-21.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.</Note>
    </Notes>
    <CVE>CVE-2009-0696</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2009-0696.html</URL>
        <Description>CVE-2009-0696</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/526185</URL>
        <Description>SUSE Bug 526185</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.</Note>
    </Notes>
    <CVE>CVE-2009-4022</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2009-4022.html</URL>
        <Description>CVE-2009-4022</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/558260</URL>
        <Description>SUSE Bug 558260</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/570912</URL>
        <Description>SUSE Bug 570912</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/644911</URL>
        <Description>SUSE Bug 644911</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.</Note>
    </Notes>
    <CVE>CVE-2010-3613</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3613.html</URL>
        <Description>CVE-2010-3613</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/657129</URL>
        <Description>SUSE Bug 657129</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.</Note>
    </Notes>
    <CVE>CVE-2010-3614</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3614.html</URL>
        <Description>CVE-2010-3614</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/657102</URL>
        <Description>SUSE Bug 657102</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.</Note>
    </Notes>
    <CVE>CVE-2010-3615</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3615.html</URL>
        <Description>CVE-2010-3615</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/657120</URL>
        <Description>SUSE Bug 657120</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.</Note>
    </Notes>
    <CVE>CVE-2011-0414</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-0414.html</URL>
        <Description>CVE-2011-0414</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/674431</URL>
        <Description>SUSE Bug 674431</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG query.</Note>
    </Notes>
    <CVE>CVE-2011-1907</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-1907.html</URL>
        <Description>CVE-2011-1907</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/692210</URL>
        <Description>SUSE Bug 692210</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.</Note>
    </Notes>
    <CVE>CVE-2011-1910</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-1910.html</URL>
        <Description>CVE-2011-1910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/696585</URL>
        <Description>SUSE Bug 696585</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/698286</URL>
        <Description>SUSE Bug 698286</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.</Note>
    </Notes>
    <CVE>CVE-2011-2464</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-2464.html</URL>
        <Description>CVE-2011-2464</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/703907</URL>
        <Description>SUSE Bug 703907</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</Note>
    </Notes>
    <CVE>CVE-2011-4313</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-4313.html</URL>
        <Description>CVE-2011-4313</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/730995</URL>
        <Description>SUSE Bug 730995</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738156</URL>
        <Description>SUSE Bug 738156</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.</Note>
    </Notes>
    <CVE>CVE-2012-1667</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-1667.html</URL>
        <Description>CVE-2012-1667</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/765315</URL>
        <Description>SUSE Bug 765315</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/792926</URL>
        <Description>SUSE Bug 792926</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.</Note>
    </Notes>
    <CVE>CVE-2012-3817</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-3817.html</URL>
        <Description>CVE-2012-3817</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/772945</URL>
        <Description>SUSE Bug 772945</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/792926</URL>
        <Description>SUSE Bug 792926</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986950</URL>
        <Description>SUSE Bug 986950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Race condition in the ns_client structure management in ISC BIND 9.9.x before 9.9.1-P2 allows remote attackers to cause a denial of service (memory consumption or process exit) via a large volume of TCP queries.</Note>
    </Notes>
    <CVE>CVE-2012-3868</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-3868.html</URL>
        <Description>CVE-2012-3868</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/772946</URL>
        <Description>SUSE Bug 772946</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/792926</URL>
        <Description>SUSE Bug 792926</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.</Note>
    </Notes>
    <CVE>CVE-2012-4244</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-4244.html</URL>
        <Description>CVE-2012-4244</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/780157</URL>
        <Description>SUSE Bug 780157</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/792926</URL>
        <Description>SUSE Bug 792926</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.</Note>
    </Notes>
    <CVE>CVE-2012-5166</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-5166.html</URL>
        <Description>CVE-2012-5166</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/784602</URL>
        <Description>SUSE Bug 784602</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/792926</URL>
        <Description>SUSE Bug 792926</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.</Note>
    </Notes>
    <CVE>CVE-2012-5688</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-5688.html</URL>
        <Description>CVE-2012-5688</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/792926</URL>
        <Description>SUSE Bug 792926</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.</Note>
    </Notes>
    <CVE>CVE-2012-5689</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-5689.html</URL>
        <Description>CVE-2012-5689</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/800822</URL>
        <Description>SUSE Bug 800822</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.</Note>
    </Notes>
    <CVE>CVE-2013-2266</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-2266.html</URL>
        <Description>CVE-2013-2266</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/811876</URL>
        <Description>SUSE Bug 811876</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/811934</URL>
        <Description>SUSE Bug 811934</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.</Note>
    </Notes>
    <CVE>CVE-2013-4854</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4854.html</URL>
        <Description>CVE-2013-4854</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/831899</URL>
        <Description>SUSE Bug 831899</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.</Note>
    </Notes>
    <CVE>CVE-2014-0591</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0591.html</URL>
        <Description>CVE-2014-0591</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/858639</URL>
        <Description>SUSE Bug 858639</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.</Note>
    </Notes>
    <CVE>CVE-2014-3214</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3214.html</URL>
        <Description>CVE-2014-3214</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.</Note>
    </Notes>
    <CVE>CVE-2014-3859</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3859.html</URL>
        <Description>CVE-2014-3859</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.</Note>
    </Notes>
    <CVE>CVE-2014-8500</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-8500.html</URL>
        <Description>CVE-2014-8500</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/908994</URL>
        <Description>SUSE Bug 908994</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986950</URL>
        <Description>SUSE Bug 986950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.</Note>
    </Notes>
    <CVE>CVE-2014-8680</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-8680.html</URL>
        <Description>CVE-2014-8680</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/908995</URL>
        <Description>SUSE Bug 908995</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.</Note>
    </Notes>
    <CVE>CVE-2015-1349</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-1349.html</URL>
        <Description>CVE-2015-1349</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/918330</URL>
        <Description>SUSE Bug 918330</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zone data and then making a query for a name in that zone.</Note>
    </Notes>
    <CVE>CVE-2015-4620</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-4620.html</URL>
        <Description>CVE-2015-4620</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936476</URL>
        <Description>SUSE Bug 936476</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.</Note>
    </Notes>
    <CVE>CVE-2015-5477</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5477.html</URL>
        <Description>CVE-2015-5477</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1000362</URL>
        <Description>SUSE Bug 1000362</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/939567</URL>
        <Description>SUSE Bug 939567</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980168</URL>
        <Description>SUSE Bug 980168</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.</Note>
    </Notes>
    <CVE>CVE-2015-5722</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.1</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5722.html</URL>
        <Description>CVE-2015-5722</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/944066</URL>
        <Description>SUSE Bug 944066</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/944107</URL>
        <Description>SUSE Bug 944107</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/954983</URL>
        <Description>SUSE Bug 954983</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958861</URL>
        <Description>SUSE Bug 958861</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="29">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.</Note>
    </Notes>
    <CVE>CVE-2015-5986</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5986.html</URL>
        <Description>CVE-2015-5986</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/944066</URL>
        <Description>SUSE Bug 944066</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/944107</URL>
        <Description>SUSE Bug 944107</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="30">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.</Note>
    </Notes>
    <CVE>CVE-2015-8000</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8000.html</URL>
        <Description>CVE-2015-8000</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/944066</URL>
        <Description>SUSE Bug 944066</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958861</URL>
        <Description>SUSE Bug 958861</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="31">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.</Note>
    </Notes>
    <CVE>CVE-2015-8704</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8704.html</URL>
        <Description>CVE-2015-8704</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/962189</URL>
        <Description>SUSE Bug 962189</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/962190</URL>
        <Description>SUSE Bug 962190</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986950</URL>
        <Description>SUSE Bug 986950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="32">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.</Note>
    </Notes>
    <CVE>CVE-2015-8705</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8705.html</URL>
        <Description>CVE-2015-8705</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/962189</URL>
        <Description>SUSE Bug 962189</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/962190</URL>
        <Description>SUSE Bug 962190</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="33">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.</Note>
    </Notes>
    <CVE>CVE-2016-1285</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1285.html</URL>
        <Description>CVE-2016-1285</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970072</URL>
        <Description>SUSE Bug 970072</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/981200</URL>
        <Description>SUSE Bug 981200</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="34">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.</Note>
    </Notes>
    <CVE>CVE-2016-1286</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.8</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1286.html</URL>
        <Description>CVE-2016-1286</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970073</URL>
        <Description>SUSE Bug 970073</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/981200</URL>
        <Description>SUSE Bug 981200</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="35">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.</Note>
    </Notes>
    <CVE>CVE-2016-2088</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2088.html</URL>
        <Description>CVE-2016-2088</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970074</URL>
        <Description>SUSE Bug 970074</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="36">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.</Note>
    </Notes>
    <CVE>CVE-2016-2776</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.8</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2776.html</URL>
        <Description>CVE-2016-2776</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1000362</URL>
        <Description>SUSE Bug 1000362</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1001595</URL>
        <Description>SUSE Bug 1001595</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1001597</URL>
        <Description>SUSE Bug 1001597</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1007829</URL>
        <Description>SUSE Bug 1007829</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="37">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.</Note>
    </Notes>
    <CVE>CVE-2016-8864</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:bind-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-chrootenv-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-doc-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-lwresd-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:bind-utils-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:idnkit-devel-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libbind9-140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libdns162-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkit1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitlite1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libidnkitres1-32bit-1.0-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs-devel-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libirs141-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisc160-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccc140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libisccfg140-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-32bit-9.10.3P4-21.1</ProductID>
        <ProductID>openSUSE Tumbleweed:liblwres141-9.10.3P4-21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-8864.html</URL>
        <Description>CVE-2016-8864</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1007829</URL>
        <Description>SUSE Bug 1007829</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1018700</URL>
        <Description>SUSE Bug 1018700</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1018701</URL>
        <Description>SUSE Bug 1018701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1018702</URL>
        <Description>SUSE Bug 1018702</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020526</URL>
        <Description>SUSE Bug 1020526</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024130</URL>
        <Description>SUSE Bug 1024130</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1033466</URL>
        <Description>SUSE Bug 1033466</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
