Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 77989 - net-dns/bind 9.3.0 CAN-2005-034 DoS with dnssec
Summary: net-dns/bind 9.3.0 CAN-2005-034 DoS with dnssec
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.uniras.gov.uk/niscc/docs/a...
Whiteboard: -3 [noglsa] jaervosz
Keywords:
: 79688 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-01-14 09:25 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-03-23 13:40 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-14 09:25:31 UTC
From Vendor-Sec:

NISCC informed me there are some BIND flaws going public on 20050125; they 
got rated "low" severity however.  Contact NISCC as normal for details, 
vulteam@niscc.gov.uk
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-14 09:30:21 UTC
vulteam@niscc.gov.uk contacted and replied that more info should be available on monday.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-17 10:00:11 UTC
Selected parts of NISCC mail follows:

Draft NISCC Vulnerability Advisory 731920/NISCC/BIND9

Vulnerability Issues with the BIND 9 Software

Severity 
--------
This is rated as low, although if exploited this could potentially result in
a denial-of-service.

Summary
-------
A weakness in the self-check function of BIND 9 have been discovered by the
Internet Systems Consortium, Inc. (ISC).

ISC have solutions available that can rectify these issues, please refer to
the 'Solution' section for further information.

Details
-------
CVE ID: CAN-2005-034

An incorrect assumption in the validator can result in an internal
consistancy test failing and this can cause named to terminate abnormally.

Mitigation
----------
ISC have recommended the following work-around:

- Disable dnssec validation (off by default) at the Options/View level

Solution
--------
ISC have released an updated version of BIND to recitify this issue:

- BIND 9.3.1

This is available from the ISC website at http://www.isc.org/sw/bind/.

Credits
-------
The NISCC Vulnerability Team would like to thank ISC for reporting this
issue to NISCC and 
for their assistance in the handling of this vulnerability.

Contact Information
-------------------
The NISCC Vulnerability Management Team can be contacted as follows:

Email      vulteam@niscc.gov.uk 
           Please quote the advisory reference in the subject line


We encourage those who wish to communicate via email to make use of our PGP
key. This is available from http://www.niscc.gov.uk/niscc/publicKey2-en.pop.

C 2005 Crown Copyright 
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-25 02:04:51 UTC
Jeffrey you're still the only daddy in metadata from a few hours ago. A security update to 9.3.1 (9.2.x is unaffected) is needed later today so you better sort out who is going to take care of that.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-25 07:55:53 UTC
This one is public now. Jeffrey please bump.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-26 05:44:27 UTC
CC'ing potential daddies. Someone please bump.
Comment 6 Carsten Lohrke (RETIRED) gentoo-dev 2005-01-27 04:08:53 UTC
*** Bug 79688 has been marked as a duplicate of this bug. ***
Comment 7 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2005-01-27 10:57:31 UTC
Security:

bind-9.3.0_rc2.ebuild is KEYWORDS="-x86 -ppc -sparc -alpha -hppa -amd64 -ia64".

9.3.1 is available only as beta2 at the moment (which I'm working on putting into the tree with the same keywords as above).
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-27 12:09:50 UTC
Thx Robin. 
Comment 9 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2005-01-28 11:29:17 UTC
Bind 9.3.1_beta2 in the tree now.
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-01-28 22:46:04 UTC
Closing without GLSA.
Comment 11 Bjarke Istrup Pedersen (RETIRED) gentoo-dev 2005-03-23 13:40:33 UTC
Since 9.3.1 final has been released, why isn't there an ebuild yet?
btw. there is a new release of dhcpd too.