<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>8838</bug_id>
          
          <creation_ts>2015-12-18 08:01:54 +0000</creation_ts>
          <short_desc>bind: CVE-2015-8000 responses with a malformed class attribute can trigger an assertion failure in db.c</short_desc>
          <delta_ts>2016-02-10 06:29:59 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>connectivity</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>1.8.2</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sona Sarmadi">sona.sarmadi</reporter>
          <assigned_to name="Sona Sarmadi">sona.sarmadi</assigned_to>
          <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>57370</commentid>
    <comment_count>0</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-12-18 08:01:54 +0000</bug_when>
    <thetext>Ref: http://www.openwall.com/lists/oss-security/2015/12/15/14

CVE:                CVE-2015-8000
Document Version:   2.0
Posting date:       15 December 2015
Program Impacted:   BIND
Versions affected:  9.0.x -&gt; 9.9.8, 9.10.0 -&gt; 9.10.3
Severity:           Critical
Exploitable:        Remotely

Description:

   An error in the parsing of incoming responses allows some records
   with an incorrect class to be accepted by BIND instead of
   being rejected as malformed.  This can trigger a REQUIRE assertion
   failure when those records are subsequently cached. Intentional
   exploitation of this condition is possible and could be used as
   a denial-of-service vector against servers performing recursive
   queries.

Impact:

   An attacker who can cause a server to request a record with a
   malformed class attribute can use this bug to trigger a REQUIRE
   assertion in db.c, causing named to exit and denying service to
   clients.  The risk to recursive servers is high. Authoritative
   servers are at limited risk if they perform authentication when
   making recursive queries to resolve addresses for servers listed
   in NS RRSETs.

CVSS Score:         7.1

CVSS Vector:        (AV:N/AC:M/Au:N/C:N/I:N/A:C)

For more information on the Common Vulnerability Scoring System and to obtain your specific environmental score please visit:
https://nvd.nist.gov/cvss.cfm?calculator&amp;version=2&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C)

Workarounds:        None.
Active exploits:    No known active exploits.

Solution:

   Upgrade to the patched release most closely related to your
   current version of BIND. Public open-source branches can be
   downloaded from http://www.isc.org/downloads.

     BIND 9 version 9.9.8-P2
     BIND 9 version 9.10.3-P2

    BIND 9 Supported Preview edition is a feature preview version
    of BIND provided exclusively to ISC Support customers.

     BIND 9 version 9.9.8-S3

Related Documents:

   See our BIND9 Security Vulnerability Matrix at
   https://kb.isc.org/article/AA-00913 for a complete listing of
   Security Vulnerabilities and versions affected.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>57371</commentid>
    <comment_count>1</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-12-18 08:22:00 +0000</bug_when>
    <thetext>Upstream commit applied to 9.9.8:

https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=490970d0614214b477085adf5aa021690194b0b8

Reference:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-8000</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>57388</commentid>
    <comment_count>2</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-12-18 15:46:13 +0000</bug_when>
    <thetext>There is one more CVE (CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c) but it affects only bind 9.9.8-P2 and bind 9.10.3-P2.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>57407</commentid>
    <comment_count>3</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2015-12-21 11:36:27 +0000</bug_when>
    <thetext>Patch sent to fido, dizzy:
http://patchwork.openembedded.org/patch/110443/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58216</commentid>
    <comment_count>4</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2016-01-26 07:57:28 +0000</bug_when>
    <thetext>Patch sent for dizzy &amp; Fido:
dizzy: 
http://git.yoctoproject.org/cgit/cgit.cgi/poky-contrib/commit/?h=akuster/dizzy-next&amp;id=7a99aa9ea73d5d12d73599c860644fc28efd5135

Fido: http://git.yoctoproject.org/cgit/cgit.cgi/poky/patch/?id=58f6a400d1df17fd89a475c62aeb7ad656439330

Remaining issue:
backport the fix to jethro</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58524</commentid>
    <comment_count>5</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2016-02-04 08:18:11 +0000</bug_when>
    <thetext>Patch has been sent for Jethro:

Patchwork [jethro-next,4/8] bind: Security fix CVE-2015-8000
http://patchwork.openembedded.org/patch/114133/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58745</commentid>
    <comment_count>6</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2016-02-08 19:50:29 +0000</bug_when>
    <thetext>Jethro patched: 
https://git.yoctoproject.org/cgit/cgit.cgi/poky/log/?h=jethro&amp;qt=grep&amp;q=CVE-2015-8000

Master is updated to 9.10.3-P3.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58808</commentid>
    <comment_count>7</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2016-02-10 06:29:59 +0000</bug_when>
    <thetext>This is fixed in all relevant branches.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>