Bug 514481 - BIND denial of service (server crash) caused by receipt of a specific remote dynamic update message
Summary: BIND denial of service (server crash) caused by receipt of a specific remote ...
Keywords:
Status: CLOSED DUPLICATE of bug 514292
Alias: None
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: bind
Version: 5.3
Hardware: All
OS: Linux
low
urgent
Target Milestone: rc
: ---
Assignee: Adam Tkac
QA Contact: BaseOS QE
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-07-29 10:18 UTC by Stefan Neufeind
Modified: 2013-04-30 23:44 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-07-29 15:29:53 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Stefan Neufeind 2009-07-29 10:18:02 UTC
https://www.isc.org/node/474

Receipt of a specially-crafted dynamic update message to a zone for which the server is the master may cause BIND 9 servers to exit. Testing indicates that the attack packet has to be formulated against a zone for which that machine is a master. Launching the attack against slave zones does not trigger the assert.

This vulnerability affects all servers that are masters for one or more zones – it is not limited to those that are configured to allow dynamic updates. Access controls will not provide an effective workaround.

Comment 1 Stefan Neufeind 2009-07-29 10:26:28 UTC
Duplicate of #514292.
(Unfortunately it seems I can't update the status of my own ticket to duplicate?)

Comment 2 Adam Tkac 2009-07-29 15:29:53 UTC

*** This bug has been marked as a duplicate of bug 514292 ***


Note You need to log in before you can comment on or make changes to this bug.