Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 367797 (CVE-2011-1907) - <net-dns/bind-9.8.0_p1: Response Policy Zones (RPZ) DoS (CVE-2011-1907)
Summary: <net-dns/bind-9.8.0_p1: Response Policy Zones (RPZ) DoS (CVE-2011-1907)
Status: RESOLVED FIXED
Alias: CVE-2011-1907
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-05-17 18:42 UTC by Christian Ruppert (idl0r)
Modified: 2011-05-22 14:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christian Ruppert (idl0r) gentoo-dev 2011-05-17 18:42:41 UTC
When Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG query.

"In BIND 9.8.0, when an RPZ was configured to replace the answer RRset for a given name, a query of type RRSIG for that name could trigger an assertion failure and cause the name server process to exit."

Affected versions: net-dns/bind-9.8.0
Fixed in: net-dns/bind-9.8.0_p1
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2011-05-17 18:48:11 UTC
~arch only, closing noglsa. no vulnerable ebuilds left in the tree.