Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 483208 (CVE-2013-3919)

Summary: <net-dns/bind-9.9.3_p2 : Denial of Service (CVE-2013-3919)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: idl0r
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [glsa]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2013-08-31 22:35:27 UTC
CVE-2013-3919 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3919):
  resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and
  9.6-ESV-R9 before 9.6-ESV-R9-P1, when a recursive resolver is configured,
  allows remote attackers to cause a denial of service (assertion failure and
  named daemon exit) via a query for a record in a malformed zone.


9.9.2 is affected, please clean. @security: GLSA vote time, vote: NO.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-31 22:45:46 UTC
(GLSA vote was mine)
Comment 2 Sergey Popov gentoo-dev 2013-09-02 08:44:13 UTC
GLSA vote: no
Comment 3 Agostino Sarubbo gentoo-dev 2013-09-03 14:14:27 UTC
Cleanup done.
Comment 4 Tobias Heinlein (RETIRED) gentoo-dev 2013-09-03 16:49:20 UTC
YES actually, added to existing request.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2014-01-29 22:52:51 UTC
This issue was resolved and addressed in
 GLSA 201401-34 at http://security.gentoo.org/glsa/glsa-201401-34.xml
by GLSA coordinator Sean Amoss (ackle).