Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 234032
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sven Wegener <swegener@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 234032 depends on: Show dependency tree
Bug 234032 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-08-05 22:19 0000
(Just converting the email sent to security@gentoo.org)

I'm restricting this, because it's not officially released. I'm preparing the
release and will commit it when it's officially released. Vulnerability type
"unspecified", decide your own classification.

<------------------------
Dear PowerDNS Distributors,                                                     

[PowerDNS security release tomorrow around 20:00 CET, small patch that          
applies cleanly referenced below]                                               

Brian Dowling of Simplicity Communications and Florian Weimer have brought      
some bad PowerDNS behaviour to my attention.                                    

In short, PowerDNS does not respond to certain queries it considers             
malformed. This in itself is not a problem, and was even thought of as a        
security measure.                                                               

Brian and Florian, independently I think, have discovered that not answering    
a query for an invalid DNS record within a valid domain allows for a larger     
spoofing window of the valid domain. Because of the Kaminsky-discovery, this    
has become bad.                                                                 

For a sophisticated attacker, this provides no benefit. However, such a long    
window allows unsophisticated hackers to achieve better results.                

The relevant patch is in:                                                       
http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1239                       
(it can also be downloaded in raw format)                                       

It applies to 2.9.21 with some innocent fuzz. The patch is in production at     
several large sites already, and has not caused problems.                       

I've also already made available PowerDNS 2.9.21.1 on                           
http://downloads.powerdns.com/releases/pdns-2.9.21.1.tar.gz                     
This consists of nothing but 2.9.21 plus this patch and a rerun of autoconf.    

I will release this update tomorrow August 6th at 20:00 hours CET.              
This issue has been assigned CVE-2008-3337.                                     

I understand this is a very short notification. I would normally not have       
made a security-only release over this, but given the current DNS climate,      
people will get upset if we aren't very vigilant.                               

Please contact me if you have questions.                                        

Kind regards,                                                                   

Bert Hubert                                                                     
PowerDNS                                                                        
<------------------------

------- Comment #1 From Sven Wegener 2008-08-06 17:07:00 0000 -------
OK, I commited it, with just "Version bump" as comment. A little bit early, but
there are other packagers that already have public reference to the new version
and it's security implication.

------- Comment #2 From Robert Buchholz 2008-08-06 17:17:56 0000 -------
Arch Security Liaisons, please test and mark stable:
=net-dns/pdns-2.9.21.1
Target keywords : "amd64 x86"

CC'ing current Liaisons:
   amd64 : keytoaster, tester
     x86 : maekke, armin76

------- Comment #3 From Robert Buchholz 2008-08-06 18:09:34 0000 -------
public via $URL

------- Comment #4 From Robert Buchholz 2008-08-06 18:10:24 0000 -------
Arches, please test and mark stable:
=net-dns/pdns-2.9.21.1
Target keywords : "amd64 x86"

------- Comment #5 From Markus Meier 2008-08-06 19:25:10 0000 -------
amd64/x86 stable, all arches done.

------- Comment #6 From Robert Buchholz 2008-08-06 21:23:18 0000 -------
vote: YES

------- Comment #7 From Pierre-Yves Rofes 2008-09-06 21:06:08 0000 -------
yes too, request filed.

------- Comment #8 From Pierre-Yves Rofes 2008-12-19 21:46:42 0000 -------
GLSA 200812-19

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug