Bug 8838 - bind: CVE-2015-8000 responses with a malformed class attribute can trigger an assertion failure in db.c
Summary: bind: CVE-2015-8000 responses with a malformed class attribute can trigger an...
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: connectivity (show other bugs)
Version: unspecified
Hardware: All Multiple
: Medium+ major
Target Milestone: 1.8.2
Assignee: Sona Sarmadi
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2015-12-18 08:01 UTC by Sona Sarmadi
Modified: 2016-02-10 06:29 UTC (History)
2 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sona Sarmadi 2015-12-18 08:01:54 UTC
Ref: http://www.openwall.com/lists/oss-security/2015/12/15/14

CVE:                CVE-2015-8000
Document Version:   2.0
Posting date:       15 December 2015
Program Impacted:   BIND
Versions affected:  9.0.x -> 9.9.8, 9.10.0 -> 9.10.3
Severity:           Critical
Exploitable:        Remotely

Description:

   An error in the parsing of incoming responses allows some records
   with an incorrect class to be accepted by BIND instead of
   being rejected as malformed.  This can trigger a REQUIRE assertion
   failure when those records are subsequently cached. Intentional
   exploitation of this condition is possible and could be used as
   a denial-of-service vector against servers performing recursive
   queries.

Impact:

   An attacker who can cause a server to request a record with a
   malformed class attribute can use this bug to trigger a REQUIRE
   assertion in db.c, causing named to exit and denying service to
   clients.  The risk to recursive servers is high. Authoritative
   servers are at limited risk if they perform authentication when
   making recursive queries to resolve addresses for servers listed
   in NS RRSETs.

CVSS Score:         7.1

CVSS Vector:        (AV:N/AC:M/Au:N/C:N/I:N/A:C)

For more information on the Common Vulnerability Scoring System and to obtain your specific environmental score please visit:
https://nvd.nist.gov/cvss.cfm?calculator&version=2&vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C)

Workarounds:        None.
Active exploits:    No known active exploits.

Solution:

   Upgrade to the patched release most closely related to your
   current version of BIND. Public open-source branches can be
   downloaded from http://www.isc.org/downloads.

     BIND 9 version 9.9.8-P2
     BIND 9 version 9.10.3-P2

    BIND 9 Supported Preview edition is a feature preview version
    of BIND provided exclusively to ISC Support customers.

     BIND 9 version 9.9.8-S3

Related Documents:

   See our BIND9 Security Vulnerability Matrix at
   https://kb.isc.org/article/AA-00913 for a complete listing of
   Security Vulnerabilities and versions affected.
Comment 2 Sona Sarmadi 2015-12-18 15:46:13 UTC
There is one more CVE (CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c) but it affects only bind 9.9.8-P2 and bind 9.10.3-P2.
Comment 3 Sona Sarmadi 2015-12-21 11:36:27 UTC
Patch sent to fido, dizzy:
http://patchwork.openembedded.org/patch/110443/
Comment 5 Sona Sarmadi 2016-02-04 08:18:11 UTC
Patch has been sent for Jethro:

Patchwork [jethro-next,4/8] bind: Security fix CVE-2015-8000
http://patchwork.openembedded.org/patch/114133/
Comment 6 Sona Sarmadi 2016-02-08 19:50:29 UTC
Jethro patched: 
https://git.yoctoproject.org/cgit/cgit.cgi/poky/log/?h=jethro&qt=grep&q=CVE-2015-8000

Master is updated to 9.10.3-P3.
Comment 7 Sona Sarmadi 2016-02-10 06:29:59 UTC
This is fixed in all relevant branches.