Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 408883 (CVE-2012-1570) - <net-dns/maradns-1.4.12: Deleted Domain Record Cache Persistence Vulnerability (CVE-2012-1570)
Summary: <net-dns/maradns-1.4.12: Deleted Domain Record Cache Persistence Vulnerabilit...
Status: RESOLVED FIXED
Alias: CVE-2012-1570
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/48492/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-03-19 16:21 UTC by Agostino Sarubbo
Modified: 2012-03-29 11:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-03-19 16:21:14 UTC
From secunia security advisory at $URL:

Description
A vulnerability has been reported in MaraDNS, which can be exploited by malicious people to conduct spoofing attacks.

The vulnerability is caused due to an error within the cache update policy, which does not properly handle revoked domain names. This can be exploited to keep a domain name resolvable after being deleted from registration.

The vulnerability is reported in versions prior to 1.3.07.15 and 1.4.12.


Solution
Update to version 1.3.07.15 and 1.4.12 or upgrade to version 2.x.


@maintainer:

do you want bump 1.4 or we can directly stabilize 2.x ?
Comment 1 MATSUU Takuto (RETIRED) gentoo-dev 2012-03-22 17:20:04 UTC
1.4.12 in cvs. please mark stable 1.4.12
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2012-03-22 17:33:34 UTC
Great, thank you.

Arches, please test and mark stable:
=net-dns/maradns-1.4.12
Target keywords : "amd64 ppc x86"
Comment 3 Agostino Sarubbo gentoo-dev 2012-03-23 10:29:41 UTC
amd64 stable
Comment 4 Myckel Habets 2012-03-24 18:36:12 UTC
Builds and runs fine on x86. Please mark stable for x86.
Comment 5 Brent Baude (RETIRED) gentoo-dev 2012-03-25 13:53:12 UTC
ppc done
Comment 6 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2012-03-27 15:02:01 UTC
x86 stable
Comment 7 Tim Sammut (RETIRED) gentoo-dev 2012-03-27 15:19:42 UTC
Thanks, everyone. GLSA Vote: no.
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2012-03-29 11:24:52 UTC
CVE-2012-1570 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1570):
  The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites
  cached server names and TTL values in NS records during the processing of a
  response to an A record query, which allows remote attackers to trigger
  continued resolvability of revoked domain names via a "ghost domain names"
  attack.
Comment 9 Sean Amoss (RETIRED) gentoo-dev Security 2012-03-29 11:29:23 UTC
GLSA vote: no.

Closing noglsa.