Bug 22424 - bind new security issue CVE-2017-3145
Summary: bind new security issue CVE-2017-3145
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA5-32-OK
Keywords: advisory, validated_update
Depends on: 22409
Blocks:
  Show dependency treegraph
 
Reported: 2018-01-19 16:15 CET by David Walser
Modified: 2018-01-24 23:38 CET (History)
1 user (show)

See Also:
Source RPM: bind-9.10.5.P3-1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-01-19 16:15:11 CET
+++ This bug was initially created as a clone of Bug #22409 +++

ISC has issued an advisory today (January 16):
https://kb.isc.org/article/AA-01542

The issue is fixed upstream in 9.11.2-P1:
https://kb.isc.org/article/AA-01550

It is also fixed in 9.10.6-P1:
https://kb.isc.org/article/AA-01548

Mageia 5 and Mageia 6 are also affected.

Cloning the bug for the Mageia 5 update.  Sysadmins, please submit it.
Comment 1 David Walser 2018-01-21 14:58:06 CET
Advisory:
========================

Updated bind packages fix security vulnerability:

BIND was improperly sequencing cleanup operations on upstream recursion fetch
contexts, leading in some cases to a use-after-free error that can trigger an
assertion failure and crash in named (CVE-2017-3145).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3145
https://kb.isc.org/article/AA-01542
https://kb.isc.org/article/AA-01548
========================

Updated packages in core/updates_testing:
========================
bind-9.10.6.P1-1.mga5
bind-sdb-9.10.6.P1-1.mga5
bind-utils-9.10.6.P1-1.mga5
bind-devel-9.10.6.P1-1.mga5
bind-doc-9.10.6.P1-1.mga5
python-bind-9.10.6.P1-1.mga5

from bind-9.10.6.P1-1.mga5.src.rpm

Assignee: sysadmin-bugs => qa-bugs

Comment 2 David Walser 2018-01-21 16:28:23 CET
Upgraded bind on my Mageia 5 i586 server; named service is still working fine.

Whiteboard: (none) => MGA5-32-OK

Lewis Smith 2018-01-21 20:33:23 CET

Keywords: (none) => advisory, validated_update
CC: (none) => sysadmin-bugs

Comment 3 Mageia Robot 2018-01-24 23:38:48 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0093.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.