<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>7098</bug_id>
          
          <creation_ts>2014-12-23 06:33:53 +0000</creation_ts>
          <short_desc>bind: delegation handling denial of service CVE-2014-8500</short_desc>
          <delta_ts>2015-02-11 17:44:58 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>connectivity</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>1.6.3</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sona Sarmadi">sona.sarmadi</reporter>
          <assigned_to name="Kai Kang">kai.kang</assigned_to>
          <cc>akuster</cc>
    
    <cc>bruce.ashfield</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>richard.purdie</cc>
    
    <cc>sgw</cc>
    
    <cc>tom.zanussi</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>47656</commentid>
    <comment_count>0</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2014-12-23 06:33:53 +0000</bug_when>
    <thetext>A denial of service flaw was found in the way BIND followed DNS delegations. A remote attacker could use a specially crafted zone containing a large number of referrals which, when looked up and processed, would cause named to use excessive amounts of memory or crash.

The BIND 9.9.6-P1 and 9.10.1-P1 release fix the following flaw:

&quot;&quot;
By making use of maliciously-constructed zones or a rogue server, an attacker can exploit an oversight in the code BIND 9 uses to follow delegations in the Domain Name Service, causing BIND to issue unlimited queries in an attempt to follow the delegation.  This can lead to resource exhaustion and denial of service (up to and including termination of the named server process.)

All recursive resolvers are affected.  Authoritative servers can be affected if an attacker can control a delegation traversed by the authoritative server in servicing the zone.
&quot;&quot;

It is reported that versions 9.0.x to 9.8.x, 9.9.0 to 9.9.6, and 9.10.0 to 9.10.1 are affected.

External References:

https://kb.isc.org/article/AA-01216/74/CVE-2014-8500%3A-A-Defect-in-Delegation-Handling-Can-Be-Exploited-to-Crash-BIND.html


Upstream commits for bind 9.9:

https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=603a0e2637b35a2da820bc807f69bcf09c682dce
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=711e833921d3dd67df7515438e152bbfdb2c1249</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>47675</commentid>
    <comment_count>1</comment_count>
    <who name="Saul Wold">sgw</who>
    <bug_when>2014-12-24 18:17:27 +0000</bug_when>
    <thetext>Please back port to 1.6.3 and 1.7.1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>48482</commentid>
    <comment_count>2</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2015-02-02 14:11:35 +0000</bug_when>
    <thetext>Was fixed in master with http://git.yoctoproject.org/cgit.cgi/poky/commit/?id=6ceceb10be5213ca3c7eb7043caebadc106da3d7</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>48496</commentid>
    <comment_count>3</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2015-02-02 17:26:34 +0000</bug_when>
    <thetext>already in Dizzy.

http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?h=dizzy&amp;id=9d20b675dd5fda3e3e8ecc9059ee7084266775cb</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>48734</commentid>
    <comment_count>4</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2015-02-11 17:44:58 +0000</bug_when>
    <thetext>Fixed in daisy too: http://git.yoctoproject.org/cgit.cgi/poky/commit/?h=daisy&amp;id=7a43fb95d1dc559b6c240f8d0c07082b3988c27c</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>