From owner-freebsd-bugs@FreeBSD.ORG Thu Jun 2 23:50:06 2011 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 12916106564A for ; Thu, 2 Jun 2011 23:50:06 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id DE46C8FC0A for ; Thu, 2 Jun 2011 23:50:05 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.4/8.14.4) with ESMTP id p52No59D012811 for ; Thu, 2 Jun 2011 23:50:05 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.4/8.14.4/Submit) id p52No5kr012810; Thu, 2 Jun 2011 23:50:05 GMT (envelope-from gnats) Resent-Date: Thu, 2 Jun 2011 23:50:05 GMT Resent-Message-Id: <201106022350.p52No5kr012810@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Ryan Steinmetz Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B6416106566B for ; Thu, 2 Jun 2011 23:46:51 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from red.freebsd.org (red.freebsd.org [IPv6:2001:4f8:fff6::22]) by mx1.freebsd.org (Postfix) with ESMTP id 8D86A8FC13 for ; Thu, 2 Jun 2011 23:46:51 +0000 (UTC) Received: from red.freebsd.org (localhost [127.0.0.1]) by red.freebsd.org (8.14.4/8.14.4) with ESMTP id p52Nkpmi002625 for ; Thu, 2 Jun 2011 23:46:51 GMT (envelope-from nobody@red.freebsd.org) Received: (from nobody@localhost) by red.freebsd.org (8.14.4/8.14.4/Submit) id p52NkpJt002624; Thu, 2 Jun 2011 23:46:51 GMT (envelope-from nobody) Message-Id: <201106022346.p52NkpJt002624@red.freebsd.org> Date: Thu, 2 Jun 2011 23:46:51 GMT From: Ryan Steinmetz To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-3.1 Cc: Subject: misc/157548: [vuxml] BIND CVE-2011-1910 X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 02 Jun 2011 23:50:06 -0000 >Number: 157548 >Category: misc >Synopsis: [vuxml] BIND CVE-2011-1910 >Confidential: no >Severity: non-critical >Priority: medium >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: change-request >Submitter-Id: current-users >Arrival-Date: Thu Jun 02 23:50:05 UTC 2011 >Closed-Date: >Last-Modified: >Originator: Ryan Steinmetz >Release: 8.2-RELEASE >Organization: Rochester Institute of Technology >Environment: >Description: CVE-2011-1910 http://www.isc.org/software/bind/advisories/cve-2011-1910 http://security.freebsd.org/advisories/FreeBSD-SA-11:02.bind.asc >How-To-Repeat: >Fix: Patch attached with submission follows: --- /tmp/vuln.xml 2011-06-02 16:50:35.000000000 -0400 +++ vuln.xml 2011-06-02 19:43:37.000000000 -0400 @@ -34,6 +34,53 @@ --> + + BIND -- Large RRSIG RRsets and Negative Caching DoS + + + bind9-sdb-ldap + bind9-sdb-postgresql + 9.4.3.4 + + + bind96 + 9.6.3.1.ESV.R4.1 + + + bind97 + 9.7.3.1 + + + bind98 + 9.8.0.2 + + + FreeBSD + 7.37.3_6 + 7.47.4_2 + 8.18.1_4 + 8.28.2_2 + + + + +

ISC reports:

+
+

A BIND 9 DNS server set up to be a caching resolver is vulnerable to a user querying a domain with very large resource record sets (RRSets) when trying to negatively cache a response. This can cause the BIND 9 DNS server (named process) to crash.

+
+ +
+ + CVE-2011-1910 + SA-11:02.bind + http://www.isc.org/software/bind/advisories/cve-2011-1910 + + + 2011-06-26 + 2011-06-02 + +
+ asterisk -- Remote crash vulnerability >Release-Note: >Audit-Trail: >Unformatted: