Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 367797 (CVE-2011-1907)

Summary: <net-dns/bind-9.8.0_p1: Response Policy Zones (RPZ) DoS (CVE-2011-1907)
Product: Gentoo Security Reporter: Christian Ruppert (idl0r) <idl0r>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: alexanderyt
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1907
Whiteboard: ~3 [noglsa]
Package list:
Runtime testing required: ---

Description Christian Ruppert (idl0r) gentoo-dev 2011-05-17 18:42:41 UTC
When Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG query.

"In BIND 9.8.0, when an RPZ was configured to replace the answer RRset for a given name, a query of type RRSIG for that name could trigger an assertion failure and cause the name server process to exit."

Affected versions: net-dns/bind-9.8.0
Fixed in: net-dns/bind-9.8.0_p1
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2011-05-17 18:48:11 UTC
~arch only, closing noglsa. no vulnerable ebuilds left in the tree.