Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 329947 (CVE-2010-2444) - <net-dns/maradns-1.4.03: DoS (CVE-2010-2444)
Summary: <net-dns/maradns-1.4.03: DoS (CVE-2010-2444)
Status: RESOLVED FIXED
Alias: CVE-2010-2444
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://maradns.org/download/maradns-1...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-07-26 15:51 UTC by Stefan Behte (RETIRED)
Modified: 2010-11-21 17:03 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-07-26 15:51:04 UTC
CVE-2010-2444 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2444):
  parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before
  1.4.03, does not properly handle hostnames that do not end in a "."
  (dot) character, which allows remote attackers to cause a denial of
  service (NULL pointer dereference) via a crafted csv2 zone file.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2010-07-26 15:52:24 UTC
Additional research required here, maybe the maintainer knows more? When will 1.4.x go stable? 
Comment 2 hiyuh 2010-07-28 15:06:12 UTC
FYI, the link to maradns-1.4.02-parse_segfault.patch at maradns.org from NVD is br0ken.
RedHat keeps local copy https://bugzilla.redhat.com/show_bug.cgi?id=600741

CAUSION: i haven't used net-dns/maradns.
Comment 3 MATSUU Takuto (RETIRED) gentoo-dev 2010-07-29 00:17:08 UTC
1.4.03 in cvs. its fixed by upstream. please mark stable 1.4.03.
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2010-08-01 12:06:28 UTC
Arches, please test and mark stable:
=net-dns/maradns-1.3.07.09-r1
Target keywords : "amd64 ppc sparc x86"
Comment 5 Markos Chandras (RETIRED) gentoo-dev 2010-08-01 12:35:19 UTC
Which one do you want?

1.4.03 or 1.3.07.09-r1 ( comments #3 and #4 )
Comment 6 Stefan Behte (RETIRED) gentoo-dev Security 2010-08-01 13:12:09 UTC
Sorry, that was an accident with the automatic script we use to generate the message. As you said in #3, 1.4.03 can be marked stable, so we take the newer version:

Arches, please test and mark stable:
=net-dns/maradns-1.4.03
Target keywords : "amd64 ppc sparc x86"
Comment 7 Christian Faulhammer (RETIRED) gentoo-dev 2010-08-01 13:53:27 UTC
Just for your notice:
* QA Notice: Files built without respecting LDFLAGS have been detected
 *  Please include the following list of files in your report:
 * /usr/sbin/zoneserver
 * /usr/sbin/maradns
 * /usr/bin/getzone
 * /usr/bin/askmara
 * /usr/bin/fetchzone
 * /usr/bin/duende
Comment 8 Christian Faulhammer (RETIRED) gentoo-dev 2010-08-01 13:57:53 UTC
x86 stable
Comment 9 Markos Chandras (RETIRED) gentoo-dev 2010-08-01 16:36:23 UTC
I patched the ebuild to respect LDFLAGS

marked stable for amd64
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2010-08-07 17:16:04 UTC
sparc stable
Comment 11 Joe Jezak (RETIRED) gentoo-dev 2010-08-11 22:37:20 UTC
Marked ppc stable.
Comment 12 Tim Sammut (RETIRED) gentoo-dev 2010-11-19 07:23:35 UTC
GLSA Vote: No.
Comment 13 Stefan Behte (RETIRED) gentoo-dev Security 2010-11-21 17:03:07 UTC
Vote: NO, closing noglsa.