An update for bind is now available for Red Hat Enterprise Linux 6.2 AdvancedUpdate Support.Red Hat Product Security has rated this update as having a security impact ofImportant.

A Common Vulnerability Scoring System (CVSS) base score, which givesa detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain NameSystem (DNS) protocols.

BIND includes a DNS server (named); a resolver library(routines for applications to use when interfacing with DNS); and tools forverifying that the DNS server is operating correctly.Security Fix(es):* A denial of service flaw was found in the way BIND parsed signature recordsfor DNAME records.

By sending a specially crafted query, a remote attacker coulduse this flaw to cause named to crash. (CVE-2016-1286)* A denial of service flaw was found in the way BIND processed certain controlchannel input.

A remote attacker able to send a malformed packet to the controlchannel could use this flaw to cause named to crash. (CVE-2016-1285)Red Hat would like to thank ISC for reporting these issues.
For details on how to apply this update, which includes the changes described inthis advisory, refer to: installing the update, the BIND daemon (named) will be restartedautomatically.Red Hat Enterprise Linux Server AUS (v. 6.2)

1315674 – CVE-2016-1285 bind: malformed packet sent to rndc can trigger assertion failure1315680 – CVE-2016-1286 bind: malformed signature records for DNAME records can trigger assertion failure

