| Summary: | bind new security issue CVE-2018-5740 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | guillomovitch, herman.viaene, marja11, sysadmin-bugs, tmb |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | mga6-64-ok, mga6-32-ok | ||
| Source RPM: | bind-9.11.3-3.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2018-08-09 14:12:11 CEST
David Walser
2018-08-09 14:12:24 CEST
Whiteboard:
(none) =>
MGA6TOO Assigning to the registered maintainer. Assignee:
bugsquad =>
guillomovitch Fixed in cauldron by 9.11.4.P1-1..mga7
David Walser
2018-08-12 18:32:27 CEST
Whiteboard:
MGA6TOO =>
(none) bind-9.10.8.P1-1.mga6 just submitted in updates_testing. Thanks Guillaume! Advisory: ======================== Updated bind packages fix security vulnerability: In ISC BIND, a defect in thie "deny-answer-aliases" feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Accidental or deliberate triggering of this defect will cause a REQUIRE assertion failure in named, causing the named process to stop execution and resulting in denial of service to clients (CVE-2018-5740). Note that only servers which have explicitly enabled the "deny-answer-aliases" feature are at risk and disabling the feature prevents exploitation. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5740 https://kb.isc.org/article/AA-01639 https://kb.isc.org/article/AA-01643 ======================== Updated packages in core/updates_testing: ======================== bind-9.10.8.P1-1.mga6 bind-sdb-9.10.8.P1-1.mga6 bind-utils-9.10.8.P1-1.mga6 bind-devel-9.10.8.P1-1.mga6 bind-doc-9.10.8.P1-1.mga6 python-bind-9.10.8.P1-1.mga6 from bind-9.10.8.P1-1.mga6.src.rpm Assignee:
guillomovitch =>
qa-bugs MGA6-32 MATE on IBM Thinkpad R50e On first test only installed bind-utils and bind-doc on this feeble laptop. Ran dig and nslookup commands against my own DNS-server on my home network. Answers are OK. I'll wait a little if someone else does the server part before I venture putting the server on this laptop and change its network settings. CC:
(none) =>
herman.viaene
Thomas Backlund
2018-08-19 19:30:39 CEST
Keywords:
(none) =>
advisory Installed server side on the laptop. Changed in MCC the network setting to a network xxx.yyy Used webmin to create an internal bind server and created record for itself and a (not existing) mach17 address. At CLI: $ nslookup mach17.xxx.yyy Server: 192.168.2.6 Address: 192.168.2.6#53 Name: mach17.xxx.yyy Address: 192.168.2.17 So bind seems to do what I wanted. Whiteboard:
(none) =>
MGA6-32-OK Works on mga infra, validating Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0353.html Status:
NEW =>
RESOLVED |