<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>20901</bug_id>
          
          <creation_ts>2009-07-29 10:23:55 +0400</creation_ts>
          <short_desc>BIND Dynamic Update DoS</short_desc>
          <delta_ts>2009-07-30 10:32:15 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>bind</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>https://www.isc.org/node/474</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Mike Lykov">combr</reporter>
          <assigned_to name="placeholder@altlinux.org">placeholder</assigned_to>
          <cc>erthad</cc>
    
    <cc>george</cc>
    
    <cc>glebfm</cc>
    
    <cc>ldv</cc>
    
    <cc>placeholder</cc>
    
    <cc>sem</cc>
    
    <cc>slev</cc>
    
    <cc>stalker</cc>
    
    <cc>vt</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>95420</commentid>
    <comment_count>0</comment_count>
    <who name="Mike Lykov">combr</who>
    <bug_when>2009-07-29 10:23:55 +0400</bug_when>
    <thetext>Receipt of a specially-crafted dynamic update message to a zone for which the server is the master may cause BIND 9 servers to exit.
Testing indicates that the attack packet has to be formulated against a zone for which that machine is a master. Launching the attack against slave zones does not trigger the assert.

This vulnerability affects all servers that are masters for one or more zones – it is not limited to those that are configured to allow dynamic updates. Access controls will not provide an effective workaround.

An active remote exploit is in wide circulation at this time.

Solution:
Upgrade BIND to one of 9.4.3-P3, 9.5.1-P3 or 9.6.1-P1.

сейчас в сизифе 
7 января 2009 Dmitry V. Levin &lt;ldv at altlinux.org&gt; 9.3.6-alt2
    * Updated to 9.3.6-P1 release.

зотелось бы видеть обновление в 4.0/updates, для Server4.0 (последний официальный релиз Server)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95422</commentid>
    <comment_count>1</comment_count>
      <attachid>3704</attachid>
    <who name="stalker">stalker</who>
    <bug_when>2009-07-29 10:30:50 +0400</bug_when>
    <thetext>Created attachment 3704
Fix из bsd</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95423</commentid>
    <comment_count>2</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2009-07-29 10:45:24 +0400</bug_when>
    <thetext>(In reply to comment #0)
&gt; сейчас в сизифе 
&gt; 7 января 2009 Dmitry V. Levin &lt;ldv at altlinux.org&gt; 9.3.6-alt2
&gt;     * Updated to 9.3.6-P1 release.

Вы что-то путаете, на момент отправки вашего сообщения в Сизифе уже был bind-9.3.6-alt5.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95427</commentid>
    <comment_count>3</comment_count>
    <who name="Mike Lykov">combr</who>
    <bug_when>2009-07-29 13:17:54 +0400</bug_when>
    <thetext>я смотрел в changelog пакета через sisyphus.ru, поэтому путать мне нечего - что написано, то скопировал.

я имел ввиду не релиз пакета, а релиз самого bind, по changelog версия самого bind в релизах пакета alt2  - alt4 не менялась.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95428</commentid>
    <comment_count>4</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2009-07-29 13:24:33 +0400</bug_when>
    <thetext>(In reply to comment #3)
&gt; я смотрел в changelog пакета через sisyphus.ru, поэтому путать мне нечего - что
&gt; написано, то скопировал.

Так бы сразу и сказали.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3704</attachid>
            <date>2009-07-29 10:30:50 +0400</date>
            <delta_ts>2009-07-29 10:44:34 +0400</delta_ts>
            <desc>Fix из bsd</desc>
            <filename>bind.patch</filename>
            <type>text/plain</type>
            <size>534</size>
            <attacher name="stalker">stalker</attacher>
            
              <data encoding="base64">SW5kZXg6IGNvbnRyaWIvYmluZDkvYmluL25hbWVkL3VwZGF0ZS5jCj09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIGNv
bnRyaWIvYmluZDkvYmluL25hbWVkL3VwZGF0ZS5jCShyZXZpc2lvbiAxOTU4NjMpCisrKyBjb250
cmliL2JpbmQ5L2Jpbi9uYW1lZC91cGRhdGUuYwkod29ya2luZyBjb3B5KQpAQCAtOTc5LDcgKzk3
OSwxMSBAQAogCQkJaWYgKHR5cGUgPT0gZG5zX3JkYXRhdHlwZV9ycnNpZyB8fAogCQkJICAgIHR5
cGUgPT0gZG5zX3JkYXRhdHlwZV9zaWcpCiAJCQkJY292ZXJzID0gZG5zX3JkYXRhX2NvdmVycygm
dC0+cmRhdGEpOwotCQkJZWxzZQorCQkJZWxzZSBpZiAodHlwZSA9PSBkbnNfcmRhdGF0eXBlX2Fu
eSkgeworCQkJCWRuc19kYl9kZXRhY2hub2RlKGRiLCAmbm9kZSk7CisJCQkJZG5zX2RpZmZfY2xl
YXIoJnRyYXNoKTsKKwkJCQlyZXR1cm4gKEROU19SX05YUlJTRVQpOworCQkJfSBlbHNlCiAJCQkJ
Y292ZXJzID0gMDsKIAogCQkJLyoK
</data>

          </attachment>
      

    </bug>

</bugzilla>