Security vulnerability in Posadis 0.50.4 and later

Meilof Veeningen <[email protected]> Wed, 29 Jan 2003 12:08:40 +0100
Newsgroups gmane.network.dns.posadis.announce
Message-ID <[email protected]>
 From http://www.posadis.org/security/0_50_8_vuln.html:


  Remote vulnerability in Posadis 0.50.x


    Products affected

    * Posadis DNS server, all platforms, versions 0.50.4 through 0.50.8


    Not affected

    * Posadis DNS server, Milestone 5 and earlier; versions 0.50.9 and
      later, or version 0.50.8 with the bugfix patch applied.
    * Poslib DNS library and applications using it, such as the Simple
      Authoritive Name Server and Pos6, the unstable 0.60.x series of
      Posadis.


    Details

Posadis versions 0.50.4 through 0.50.8 contain a bug, causing them not 
to properly check whether specific DNS messages contain a question 
section. Thus, Posadis might try to read from a NULL memory location. 
This bug, which was discovered in an internal test, allows any person to 
crash the DNS server by sending a malformed packet to it. It is not 
known whether this bug can be used to execute arbitrary code on the server.


    Solution

Users of Posadis 0.50.8 and earlier should upgrade as soon as possible. 
I will release a new Posadis version, 0.50.9, as soon as possible, but 
for now, try one of the following:

    * Download a new source tarball: posadis-0.50.8a.tar.gz
      <http://www.posadis.org/files/posadis-0.50.8a.tar.gz> (md5sum
      a98f3075d425eb8d87685da13c2d01a6)
    * Download a patch from the Posadis 0.50.8 sources: pos-0.50.8-fix
      <http://www.posadis.org/files/pos-0.50.8-fix> (md5sum
      f38026481ee946cc9755b742211b3582)
    * Download a new Posadis binary for Linux: posadis-0.50.8-fixed
      <http://www.posadis.org/files/posadis-0.50.8-fixed> (md5sum
      d3d92e7871e532a5cee6ecb33136bfa6)

A Windows binary will follow shortly.



-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com