Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 588658 (CVE-2016-6173) - <net-dns/nsd-4.1.11: Malicious primary DNS servers can crash secondaries
Summary: <net-dns/nsd-4.1.11: Malicious primary DNS servers can crash secondaries
Status: RESOLVED FIXED
Alias: CVE-2016-6173
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-12 08:39 UTC by Agostino Sarubbo
Modified: 2016-10-14 14:00 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
$ diff -u /usr/portage/net-dns/nsd/nsd-4.1.10.ebuild nsd-4.1.11.ebuild (file_588658.txt,897 bytes, text/plain)
2016-08-26 15:39 UTC, Tom Hendrikx
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-07-12 08:39:54 UTC
From ${URL} :

It turns out that most DNS server implementations do not implement 
reasonable restrictions for zone sizes.  This allows an explicitly 
configured primary DNS server for a zone to crash a secondary DNS 
server, affecting service of other zones hosted on the same secondary 
server.

Some references:

https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015058.html
https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015075.html
https://gitlab.labs.nic.cz/labs/knot/merge_requests/541
https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=790

PowerDNS is reportedly affected as well, but I did not find a public bug 
for this issue.


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2016-08-24 22:18:13 UTC
According to the ChangeLog of nsd-4.1.11 this has been fixed.

@Tom: Can we stabilize this version anytime soon?
Comment 2 Tom Hendrikx 2016-08-26 15:37:12 UTC
I did a quick test and a simple version bump will do fine for 4.1.11 (after removing the nsd-4.1.10 specific ipv6 patch, which is included upstream in 4.1.11).

As far as the glsa tag in whiteboard: the nsd developers didn't think an emergency release for this issue was necessary. But the Security should have the final take on the glsa anyway.
Comment 3 Tom Hendrikx 2016-08-26 15:39:16 UTC
Created attachment 444200 [details]
$ diff -u /usr/portage/net-dns/nsd/nsd-4.1.10.ebuild nsd-4.1.11.ebuild
Comment 4 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2016-09-07 09:38:18 UTC
No version of this package has ever been stabilized. Dunno if it's still woth a GLSA.
Comment 5 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2016-09-07 09:38:32 UTC
I mean "worth" of course.
Comment 6 Yury German Gentoo Infrastructure gentoo-dev 2016-09-10 07:18:57 UTC
No stable versions, closing as noglsa.
Comment 7 Aaron Bauman (RETIRED) gentoo-dev 2016-10-14 14:00:15 UTC
Is 3.2.22 not affected by this?(In reply to Yury German from comment #6)
> No stable versions, closing as noglsa.

Closing.