Ondřej Surý
b04cb88462
Fix off-by-one bug in ISC SPNEGO implementation
...
The ISC SPNEGO implementation is based on mod_auth_kerb code. When
CVE-2006-5989 was disclosed, the relevant fix was not applied to the
BIND 9 codebase, making the latter vulnerable to the aforementioned flaw
when "tkey-gssapi-keytab" or "tkey-gssapi-credential" is set in
named.conf.
The original description of CVE-2006-5989 was:
Off-by-one error in the der_get_oid function in mod_auth_kerb 5.0
allows remote attackers to cause a denial of service (crash) via a
crafted Kerberos message that triggers a heap-based buffer overflow
in the component array.
Later research revealed that this flaw also theoretically enables remote
code execution, though achieving the latter in real-world conditions is
currently deemed very difficult.
This vulnerability was responsibly reported as ZDI-CAN-12302 ("ISC BIND
TKEY Query Heap-based Buffer Overflow Remote Code Execution
Vulnerability") by Trend Micro Zero Day Initiative.
2021-02-17 22:36:08 +01:00
..
2021-02-16 12:08:21 +11:00
2021-02-12 10:43:19 +11:00
2021-02-17 12:46:25 +01:00
2021-01-29 10:35:26 +01:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-11-11 16:06:23 -03:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-30 14:26:26 +02:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-02-08 15:13:49 +11:00
2020-09-14 16:50:58 -07:00
2021-02-08 15:13:49 +11:00
2020-09-14 16:50:58 -07:00
2020-11-25 13:21:58 +01:00
2021-02-08 15:13:49 +11:00
2020-09-14 16:50:58 -07:00
2020-11-11 15:59:56 -03:00
2020-12-23 11:56:44 +01:00
2021-02-16 12:08:21 +11:00
2020-09-14 16:50:58 -07:00
2021-02-16 12:08:21 +11:00
2021-02-16 12:08:21 +11:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-02-08 15:13:49 +11:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-02-16 12:08:21 +11:00
2021-02-16 12:08:21 +11:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-01-26 12:38:32 +01:00
2021-01-12 13:13:05 +01:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-02-03 15:48:20 +01:00
2021-02-08 15:13:49 +11:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-01-25 15:28:09 +01:00
2020-09-14 16:50:58 -07:00
2020-09-25 08:21:24 +02:00
2020-09-30 14:26:26 +02:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-11-26 14:15:05 +00:00
2020-09-14 16:50:58 -07:00
2021-02-08 15:13:49 +11:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-01-26 15:04:59 +01:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-10-02 08:50:51 +02:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-12-01 23:19:20 +11:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-12-08 19:34:05 +01:00
2021-02-08 16:07:43 +01:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-02-08 15:13:49 +11:00
2020-11-26 14:15:05 +00:00
2020-09-14 16:50:58 -07:00
2021-02-08 15:13:49 +11:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-11-11 15:59:56 -03:00
2020-11-11 15:59:56 -03:00
2020-09-14 16:50:58 -07:00
2020-12-08 19:34:05 +01:00
2020-09-14 16:50:58 -07:00
2021-02-17 22:36:08 +01:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-29 10:40:56 +10:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-02-16 12:08:21 +11:00
2020-09-14 16:50:58 -07:00
2020-09-14 16:50:58 -07:00
2021-02-08 15:13:49 +11:00
2020-09-14 16:50:58 -07:00
2020-12-23 11:56:33 +01:00
2020-10-30 08:21:43 +11:00
2021-01-25 15:28:09 +01:00
2021-02-16 12:08:21 +11:00
2021-01-26 12:38:32 +01:00
2020-11-26 14:15:05 +00:00
2021-02-15 11:52:50 -03:00
2020-09-14 16:50:58 -07:00
2021-01-28 12:18:31 +11:00
2021-02-08 15:13:49 +11:00