Bug 983273 (CVE-2015-8899) - VUL-1: CVE-2015-8899: dnsmasq: denial of service between local and remote dns entries
Summary: VUL-1: CVE-2015-8899: dnsmasq: denial of service between local and remote dns...
Status: RESOLVED FIXED
: 1012019 (view as bug list)
Alias: CVE-2015-8899
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/169786/
Whiteboard: CVSSv2:SUSE:CVE-2015-8899:4.3:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-06-06 12:33 UTC by Marcus Meissner
Modified: 2017-06-20 12:45 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Marcus Meissner 2016-06-06 12:38:21 UTC
sle11 sp2 and older do not seem to have the code.

we introduce the buggy? code in our 2.71 versions by a local patch
dnsmasq-local-cache.patch
Comment 2 Marcus Meissner 2016-06-06 12:39:20 UTC
so sle11 sp3, sp4, sle12 ga anbd sp1 codestreams affected
Comment 3 Marcus Meissner 2016-06-06 12:39:45 UTC
http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2016q2/010479.html

has some form of reproducer.
Comment 4 Marcus Meissner 2016-06-06 12:41:21 UTC
(so far not considering an update, as this is largely a local issue)
Comment 5 Swamp Workflow Management 2016-06-06 22:02:28 UTC
bugbot adjusting priority
Comment 6 Reinhard Max 2016-08-03 17:38:09 UTC
Upstream version 2.75 was affected as well, and I've just upgraded Factory to 2.76, which already contains the fix.

(In reply to Marcus Meissner from comment #4)
> (so far not considering an update, as this is largely a local issue)

So, can we close this, or how shall we proceed?
Comment 7 Bernhard Wiedemann 2016-08-03 18:00:33 UTC
This is an autogenerated message for OBS integration:
This bug (983273) was mentioned in
https://build.opensuse.org/request/show/416775 Factory / dnsmasq
Comment 9 Marcus Meissner 2016-09-28 12:03:32 UTC
please submit if you want to gt it off your list, we will stage it for further updates.
Comment 10 Reinhard Max 2016-10-05 17:07:04 UTC
Done.
Comment 12 Reinhard Max 2016-12-12 17:03:14 UTC
*** Bug 1012019 has been marked as a duplicate of this bug. ***
Comment 13 Reinhard Max 2016-12-12 17:08:22 UTC
Maybe we should release this, given that customers actually hit the crash.
Comment 14 Marcus Meissner 2016-12-12 18:41:43 UTC
I will queue the incidents for QA now.
Comment 15 Swamp Workflow Management 2016-12-20 16:07:59 UTC
SUSE-SU-2016:3199-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 983273
CVE References: CVE-2015-8899
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    dnsmasq-2.71-0.16.3
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    dnsmasq-2.71-0.16.3
Comment 16 Swamp Workflow Management 2016-12-23 15:09:14 UTC
SUSE-SU-2016:3257-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 983273
CVE References: CVE-2015-8899
Sources used:
SUSE OpenStack Cloud Compute 5 (src):    dnsmasq-2.71-6.3.1
Comment 17 Swamp Workflow Management 2016-12-23 20:08:17 UTC
SUSE-SU-2016:3269-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 983273
CVE References: CVE-2015-8899
Sources used:
SUSE OpenStack Cloud 6 (src):    dnsmasq-2.71-13.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    dnsmasq-2.71-13.1
SUSE Linux Enterprise Server 12-SP2 (src):    dnsmasq-2.71-13.1
SUSE Linux Enterprise Server 12-SP1 (src):    dnsmasq-2.71-13.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    dnsmasq-2.71-13.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    dnsmasq-2.71-13.1
Comment 18 Swamp Workflow Management 2017-01-03 19:08:09 UTC
openSUSE-SU-2017:0016-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 983273
CVE References: CVE-2015-8899
Sources used:
openSUSE Leap 42.2 (src):    dnsmasq-2.71-8.1
openSUSE Leap 42.1 (src):    dnsmasq-2.71-9.1
Comment 19 Marcus Meissner 2017-06-20 12:45:19 UTC
released