Bug 987873 (CVE-2016-6713) - VUL-0: CVE-2016-6173: nsd: malicious primary DNS servers can crash secondaries
Summary: VUL-0: CVE-2016-6173: nsd: malicious primary DNS servers can crash secondaries
Status: RESOLVED FIXED
Alias: CVE-2016-6713
Product: openSUSE.org
Classification: openSUSE
Component: 3rd party software (show other bugs)
Version: unspecified
Hardware: Other All
: P3 - Medium : Major (vote)
Target Milestone: ---
Assignee: Adam Majer
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-06 12:36 UTC by Andreas Stieger
Modified: 2017-01-04 13:53 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-07-06 12:36:29 UTC
Courtesy bug from the SUSE security team for server:dns/nsd

via oss-sec http://seclists.org/oss-sec/2016/q3/19

"most DNS server implementations do not implement reasonable restrictions for zone sizes. This allows an explicitly configured primary DNS server for a zone to crash a secondary DNS server, affecting service of other zones hosted on the same secondary server."

from https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015058.html

> * [ For [LT] Secondary DNS Service ]
> 
>   See https://github.com/sischkg/xfer-limit
> 
>   Most of authoritative DNS server softwares do not have size limit of
>   zone transfer. He generated unlimited zone information at master
>   server, and transfered to slave servers. BIND 9, knot DNS and Power
>   DNS slave servers received unlimited zone informataion and died.
>   NSD slave DNS server received unlimited zone data and /tmp became full.
> 
>   He generated zone transfer size limit patch for BIND 9, Knot, NSD,
>   PowerDNS.

Third party patches at https://github.com/sischkg/xfer-limit

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6173
http://seclists.org/oss-sec/2016/q3/20
Comment 1 Swamp Workflow Management 2016-07-06 22:01:03 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2016-07-07 06:35:18 UTC
I believe Marcus said that nsd already had a fix.
Comment 3 Adam Majer 2017-01-04 13:53:26 UTC
This is fixed in server:dns/nsd since r27 or version 4.1.13.