Bug 856754 (CVE-2012-4244)
Summary: | CVE-2012-4244 bind: specially crafted resource record causes named to exit | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vincent Danen <vdanen> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | high | Docs Contact: | |||||
Priority: | high | ||||||
Version: | unspecified | CC: | atkac, ian.bobbitt, raina, roomojee, thozza, timm2k, tkubota, yamato, yohmura, zzhou | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2012-09-15 16:31:22 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 856756, 856904, 856905, 856906, 856907, 856908, 856909, 859916 | ||||||
Bug Blocks: | 856774 | ||||||
Attachments: |
|
Description
Vincent Danen
2012-09-12 18:11:16 UTC
Created attachment 612201 [details]
diff of bind-9.6-ESV-R7-P2 to P3
--- 9.6-ESV-R7-P3 released ---
3364. [security] Named could die on specially crafted record.
[RT #30416]
3358 [bug] Fix declaration of fatal in bin/named/server.c
and bin/nsupdate/main.c. [RT #30522]
(I didn't pull out the irrelevant changes as I suspect they may be used by the pertinent changes)
Created bind tracking bugs for this issue Affects: fedora-all [bug 856756] This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:1268 https://rhn.redhat.com/errata/RHSA-2012-1268.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2012:1267 https://rhn.redhat.com/errata/RHSA-2012-1267.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2012:1266 https://rhn.redhat.com/errata/RHSA-2012-1266.html bind-9.9.1-9.P3.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report. bind-9.9.1-10.P3.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report. bind-9.8.3-4.P3.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report. This issue has been addressed in following products: Red Hat Enterprise Linux 4 Extended Lifecycle Support Via RHSA-2012:1365 https://rhn.redhat.com/errata/RHSA-2012-1365.html |