Bug 7098 - bind: delegation handling denial of service CVE-2014-8500
Summary: bind: delegation handling denial of service CVE-2014-8500
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: connectivity (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 1.6.3
Assignee: Kai Kang
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2014-12-23 06:33 UTC by Sona Sarmadi
Modified: 2015-02-11 17:44 UTC (History)
7 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sona Sarmadi 2014-12-23 06:33:53 UTC
A denial of service flaw was found in the way BIND followed DNS delegations. A remote attacker could use a specially crafted zone containing a large number of referrals which, when looked up and processed, would cause named to use excessive amounts of memory or crash.

The BIND 9.9.6-P1 and 9.10.1-P1 release fix the following flaw:

""
By making use of maliciously-constructed zones or a rogue server, an attacker can exploit an oversight in the code BIND 9 uses to follow delegations in the Domain Name Service, causing BIND to issue unlimited queries in an attempt to follow the delegation.  This can lead to resource exhaustion and denial of service (up to and including termination of the named server process.)

All recursive resolvers are affected.  Authoritative servers can be affected if an attacker can control a delegation traversed by the authoritative server in servicing the zone.
""

It is reported that versions 9.0.x to 9.8.x, 9.9.0 to 9.9.6, and 9.10.0 to 9.10.1 are affected.

External References:

https://kb.isc.org/article/AA-01216/74/CVE-2014-8500%3A-A-Defect-in-Delegation-Handling-Can-Be-Exploited-to-Crash-BIND.html


Upstream commits for bind 9.9:

https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=603a0e2637b35a2da820bc807f69bcf09c682dce
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=711e833921d3dd67df7515438e152bbfdb2c1249
Comment 1 Saul Wold 2014-12-24 18:17:27 UTC
Please back port to 1.6.3 and 1.7.1