Bug 1411377 (CVE-2016-9444) - CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response
Summary: CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS r...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-9444
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact: Petr Sklenar
URL:
Whiteboard:
Depends On: 1411417 1411418 1412462 1412463 1457189
Blocks: 1411339
TreeView+ depends on / blocked
 
Reported: 2017-01-09 15:10 UTC by Dhiru Kholia
Modified: 2021-02-17 02:48 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A denial of service flaw was found in the way BIND handled an unusually-formed DS record response. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Clone Of:
Environment:
Last Closed: 2017-07-25 20:46:11 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:0062 0 normal SHIPPED_LIVE Important: bind security update 2017-01-16 10:51:03 UTC
Red Hat Product Errata RHSA-2017:1583 0 normal SHIPPED_LIVE Important: bind security and bug fix update 2017-06-28 13:00:18 UTC

Description Dhiru Kholia 2017-01-09 15:10:40 UTC
An unusually-formed answer containing a DS resource record could trigger an assertion failure. While the combination of properties which triggers the assertion should not occur in normal traffic, it is potentially possible for the assertion to be triggered deliberately by an attacker sending a specially-constructed answer having the required properties.

This vulnerability occurs during the processing of an answer packet received in response to a query. As a result, recursive servers are at the greatest risk; authoritative servers are at risk only to the extent that they perform a limited set of queries.

This description is borrowed from the upstream advisory.

Comment 1 Dhiru Kholia 2017-01-09 15:10:56 UTC
Acknowledgments:

Name: ISC

Comment 4 Dhiru Kholia 2017-01-12 05:17:55 UTC
Created bind tracking bugs for this issue:

Affects: fedora-all [bug 1412462]

Comment 5 Dhiru Kholia 2017-01-12 05:18:01 UTC
Created bind99 tracking bugs for this issue:

Affects: fedora-all [bug 1412463]

Comment 6 Dhiru Kholia 2017-01-12 05:18:42 UTC
External References:

https://kb.isc.org/article/AA-01441

Comment 7 errata-xmlrpc 2017-01-16 05:51:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:0062 https://rhn.redhat.com/errata/RHSA-2017-0062.html

Comment 9 errata-xmlrpc 2017-06-28 09:01:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.2 Extended Update Support

Via RHSA-2017:1583 https://access.redhat.com/errata/RHSA-2017:1583


Note You need to log in before you can comment on or make changes to this bug.