Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 427966 (CVE-2012-3817) - <net-dns/bind-9.9.1_p2 Multiple vulnerabilities (CVE-2012-{3817,3868})
Summary: <net-dns/bind-9.9.1_p2 Multiple vulnerabilities (CVE-2012-{3817,3868})
Status: RESOLVED FIXED
Alias: CVE-2012-3817
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://kb.isc.org/article/AA-00719
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-07-24 23:20 UTC by Sean Amoss (RETIRED)
Modified: 2012-09-24 00:30 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sean Amoss (RETIRED) gentoo-dev Security 2012-07-24 23:20:37 UTC
From upstream release notes at $URL:

Security Fixes

Prevents a named assert (crash) when validating caused by using "Bad cache" data before it has been initialized.  [RT #30025] 

A condition has been corrected where improper handling of zero-length RDATA could cause undesirable behavior, including termination of the named process.  [RT #29644]

Also see:
https://kb.isc.org/article/AA-00729
https://kb.isc.org/article/AA-00730
Comment 1 Christian Ruppert (idl0r) gentoo-dev 2012-07-25 17:56:13 UTC
9.8.3-P2 and 9.9.1-P2 are in the tree now.
Please prefer 9.9.1-P2 over 9.8.3-P2 in case you want to stabilize any of those versions.
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-07-26 12:28:56 UTC
(In reply to comment #1)
> 9.8.3-P2 and 9.9.1-P2 are in the tree now.
> Please prefer 9.9.1-P2 over 9.8.3-P2 in case you want to stabilize any of
> those versions.

Thanks, Christian.

Arches, please test and mark stable:
=net-dns/bind-9.9.1_p2
Target KEYWORDS="alpha amd64 arm hppa ia64 ~mips ppc ~ppc64 s390 sh sparc x86 ~x86-fbsd"
Comment 3 Jeroen Roovers (RETIRED) gentoo-dev 2012-07-26 19:56:37 UTC
Stable for HPPA.
Comment 4 Jeff (JD) Horelick (RETIRED) gentoo-dev 2012-07-27 08:14:32 UTC
x86 stable
Comment 5 Richard Freeman gentoo-dev 2012-07-27 15:27:26 UTC
amd64 stable
Comment 6 Anthony Basile gentoo-dev 2012-07-27 15:56:24 UTC
Stable ppc/ppc64
Comment 7 Anthony Basile gentoo-dev 2012-07-27 16:20:28 UTC
Okay I hit this while trying to stabilize on arm, but it is going to be a problem on all arches (tested on amd64 just to be sure).  If one builds openssl with USE="bindist", then openssl is built without gost support.  If one then tries to build bind with USE="gost", bind configure fails with:

    checking for OpenSSL GOST support... no


Obviously.

Since this is a corner case, and we're addressing a security issue, I'll continue with arm stabilization.  The maintainers may want to address this post-stabilization with some REQUIRED_USE constraint.
Comment 8 Anthony Basile gentoo-dev 2012-07-27 16:38:24 UTC
Stable arm
Comment 9 Christian Ruppert (idl0r) gentoo-dev 2012-07-28 21:28:16 UTC
(In reply to comment #7)
> Okay I hit this while trying to stabilize on arm, but it is going to be a
> problem on all arches (tested on amd64 just to be sure).  If one builds
> openssl with USE="bindist", then openssl is built without gost support.  If
> one then tries to build bind with USE="gost", bind configure fails with:
> 
>     checking for OpenSSL GOST support... no
> 
> 
> Obviously.
> 
> Since this is a corner case, and we're addressing a security issue, I'll
> continue with arm stabilization.  The maintainers may want to address this
> post-stabilization with some REQUIRED_USE constraint.

The OpenSSL dependency when using GOST has been fixed in all versions to depend on openssl[-bindist].
Comment 10 Stefan Behte (RETIRED) gentoo-dev Security 2012-08-08 09:33:50 UTC
*ping*
Comment 11 Raúl Porcel (RETIRED) gentoo-dev 2012-08-19 14:11:58 UTC
alpha/ia64/s390/sh/sparc stable
Comment 12 Tim Sammut (RETIRED) gentoo-dev 2012-08-19 17:11:51 UTC
Thanks, folks. GLSA Vote: yes.
Comment 13 Sean Amoss (RETIRED) gentoo-dev Security 2012-08-20 00:05:39 UTC
GLSA vote: yes.

Drafted GLSA.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2012-09-24 00:30:49 UTC
This issue was resolved and addressed in
 GLSA 201209-04 at http://security.gentoo.org/glsa/glsa-201209-04.xml
by GLSA coordinator Sean Amoss (ackle).