Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 483208 (CVE-2013-3919) - <net-dns/bind-9.9.3_p2 : Denial of Service (CVE-2013-3919)
Summary: <net-dns/bind-9.9.3_p2 : Denial of Service (CVE-2013-3919)
Status: RESOLVED FIXED
Alias: CVE-2013-3919
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-08-31 22:35 UTC by GLSAMaker/CVETool Bot
Modified: 2014-01-29 22:52 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2013-08-31 22:35:27 UTC
CVE-2013-3919 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3919):
  resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and
  9.6-ESV-R9 before 9.6-ESV-R9-P1, when a recursive resolver is configured,
  allows remote attackers to cause a denial of service (assertion failure and
  named daemon exit) via a query for a record in a malformed zone.


9.9.2 is affected, please clean. @security: GLSA vote time, vote: NO.
Comment 1 Chris Reffett gentoo-dev Security 2013-08-31 22:45:46 UTC
(GLSA vote was mine)
Comment 2 Sergey Popov gentoo-dev Security 2013-09-02 08:44:13 UTC
GLSA vote: no
Comment 3 Agostino Sarubbo gentoo-dev 2013-09-03 14:14:27 UTC
Cleanup done.
Comment 4 Tobias Heinlein (RETIRED) gentoo-dev 2013-09-03 16:49:20 UTC
YES actually, added to existing request.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2014-01-29 22:52:51 UTC
This issue was resolved and addressed in
 GLSA 201401-34 at http://security.gentoo.org/glsa/glsa-201401-34.xml
by GLSA coordinator Sean Amoss (ackle).