Bug 864273 (CVE-2012-5166)
Summary: | CVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Huzaifa S. Sidhpurwala <huzaifas> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | high | Docs Contact: | |||||
Priority: | high | ||||||
Version: | unspecified | CC: | atkac, jlieskov, johan.bergstrom, raina, rpacheco, rwahyudi, security-response-team, zzhou | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2012-10-12 20:38:27 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 859916, 864748, 864749, 864750, 864751, 864753, 864754, 864756 | ||||||
Bug Blocks: | 863382 | ||||||
Attachments: |
|
Description
Huzaifa S. Sidhpurwala
2012-10-09 03:17:11 UTC
External References: https://kb.isc.org/article/AA-00801 Created attachment 624300 [details]
diff of bind-9.6-ESV-R7-P3 to P4
The relevant bits of the diff between versions with this changelog entry:
3383. [security] A certain combination of records in the RBT could
cause named to hang while populating the additional
section of a response. [RT #31090]
This issue affects the version of bind as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the version of bind97 as shipped with Red Hat Enterprise Linux 5. This issue affects the version of bind as shipped with Fedora 16 and Fedora 17 Created bind tracking bugs for this issue Affects: fedora-all [bug 864756] This issue has been addressed in following products: Red Hat Enterprise Linux 4 Extended Lifecycle Support Via RHSA-2012:1365 https://rhn.redhat.com/errata/RHSA-2012-1365.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2012:1364 https://rhn.redhat.com/errata/RHSA-2012-1364.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2012:1363 https://rhn.redhat.com/errata/RHSA-2012-1363.html dhcp-4.2.4-16.P2.fc17, bind-dyndb-ldap-1.1.0-0.15.rc1.fc17, bind-9.9.2-2.fc17, dnsperf-2.0.0.0-2.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report. dhcp-4.2.4-18.P2.fc18, bind-dyndb-ldap-2.0-0.3.20121009git6a86b1.fc18, bind-9.9.2-2.fc18, dnsperf-2.0.0.0-3.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report. dhcp-4.2.4-4.P2.fc16, bind-dyndb-ldap-1.1.0-0.15.rc1.fc16, bind-9.8.4-2.fc16, dnsperf-2.0.0.0-2.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report. |