Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

June 19th, 2019

Multiple vulnerabilities were found in 3rd party software running on the Men & Mice appliances.

  • A vulnerability, CVE-2019-6471 was found in 3rd party software running on our DNS/DHCP appliance.

    A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c.

    An attacker who can cause a resolver to perform queries which will be answered by a server which responds with deliberately malformed answers can cause named to exit, denying service to clients.

    For more information, see https://kb.isc.org/docs/cve-2019-6471.

  • Multiple vulnerabilities, CVE-2019-11477, CVE-2019-11478 & CVE-2019-11479, were found in the Linux kernel that is used on the Men & Mice appliances
    In some cases, the vulnerability could allow an attacker to trigger a kernel panic in the system.  

We recommend that all Men & Mice Appliances are upgraded to the latest version, 9.2.4.


Updates to the other supported branches, 8.3 and 9.1 will follow.  

 

The appliances can be easily upgraded using the Automatic Updates feature of the Men & Mice Suite.
For details on how to update the Men & Mice Suite, see 

https://docs.menandmice.com/display/MM/Updating+the+Men+and+Mice+Suite 

For more information regarding the upgrade, contact Men & Mice Support using the link below
https://docs.menandmice.com/display/MM/Contacting+Support

April 25th, 2019

A vulnerability, CVE-2018-5743 was found in 3rd party software running on our DNS/DHCP appliance.

A defect in BIND's handling the number of TCP clients could allow an attacker to grow the number of simultaneous connections beyond the limit, which would result in unexpected and unreliable behavior.

For more information, see https://kb.isc.org/docs/cve-2018-5743.

 

We recommend that all Men & Mice DNS/DHCP Appliances are upgraded to the latest version, either 9.1.11 or 9.2.2.

 

The appliances can be easily upgraded using the Automatic Updates feature of the Men & Mice Suite.
For details on how to update the Men & Mice Suite, see

https://docs.menandmice.com/display/MM/Updating+the+Men+and+Mice+Suite

 

For more information regarding the upgrade, contact Men & Mice Support using the link below
https://docs.menandmice.com/display/MM/Contacting+Support

September 20th, 2018

This is an critical operational announcement from Men & Mice.

...

We recommend that all Men & Mice Appliances are upgraded to the latest version, which is 9.1.4.
The appliances on the 8.3 and 8.1 versions will be updated shortlyavailable on the 26th of September 2018.

The appliances can be easily upgraded using the Automatic Updates feature of the Men & Mice Suite.
For details on how to update the Men & Mice Suite, see

...