Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 247079 (CVE-2008-5277) - net-dns/pdns <2.9.21.2 DNS HINFO crash (CVE-2008-5277)
Summary: net-dns/pdns <2.9.21.2 DNS HINFO crash (CVE-2008-5277)
Status: RESOLVED FIXED
Alias: CVE-2008-5277
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://marc.info/?l=pdns-dev&m=122671...
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-11-16 15:35 UTC by Robert Buchholz (RETIRED)
Modified: 2008-12-19 21:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-11-16 15:35:33 UTC
Certian HINFO DNS requests can crash PowerDNS threads or (reportedly) the whole server. This is more severe when running with 'distributor-threads=1'.

The fixed version will be released tomorrow, let's get it into portage asap.
Comment 1 Sven Wegener gentoo-dev 2008-11-16 20:42:11 UTC
pdns-2.9.21.2 is in the tree.
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-16 21:39:15 UTC
I thought we should have waited with submitting to portage until 2008-11-17?

Arches, please test and mark stable.
'=net-dns/pdns-2.9.21.2'

Target keywords: x86, amd64
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-11-17 01:51:37 UTC
(In reply to comment #2)
> I thought we should have waited with submitting to portage until 2008-11-17?

No, if it is SEMI-PUBLIC, we usually handle stabling in the tree.

> Arches, please test and mark stable.
> '=net-dns/pdns-2.9.21.2'
> 
> Target keywords: x86, amd64

You can't cc arches to a restricted bug as arch developers cannot access it (only the alias login can). CC'ing arch liaisons:

   amd64 : keytoaster, tester
     x86 : maekke, armin76


Comment 4 Markus Meier gentoo-dev 2008-11-19 22:21:47 UTC
amd64/x86 stable, all arches done.
Comment 5 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-19 23:39:11 UTC
Reopening.
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2008-11-20 03:12:29 UTC
public via http://doc.powerdns.com/powerdns-advisory-2008-03.html
Comment 7 Robert Buchholz (RETIRED) gentoo-dev 2008-12-16 21:54:36 UTC
Let's GLSA this with bug 234032. YES.
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-12-19 21:46:53 UTC
GLSA 200812-19