Bug 928011 (CVE-2013-2494)
Summary: | CVE-2013-2494 dhcp: bind/libdns CVE-2013-2266 regular expressions excessive resource consumption DoS | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED DUPLICATE | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | atkac, jpopelka, thozza |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-03-27 10:36:35 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 928048 |
Description
Jan Lieskovsky
2013-03-26 17:03:56 UTC
Release notes indicate: - A security issue in Bind9 was found and fixed. This release includes the fixed Bind9 code. There have been no code changes to the DHCP code. [ISC-Bugs #32688] CVE: CVE-2013-2266 DHCP update upgrades used Bind version to fix CVE-2013-2266 (bug 928027). There should be no separate CVE id assigned for DHCP just because it's different application that uses/embeds vulnerable Bind code. Fedora dhcp builds remove embed bind source and link against system libdns: http://pkgs.fedoraproject.org/cgit/dhcp.git/tree/dhcp.spec?id=4a364d130b918caed6d357fd5a1fcc2c35926851#n176 Statement: Not Vulnerable. This issue does not affect the version of dhcp as shipped with Red Hat Enterprise Linux 5 and 6. *** This bug has been marked as a duplicate of bug 928027 *** This issue does not affect the version of dhcp as shipped with Fedora 17 and Fedora 18. More details in comment #7 |