Your message dated Sun, 29 Oct 2023 10:49:24 +0000
with message-id <[email protected]>
and subject line Bug#1035936: fixed in maradns 2.0.13-1.5
has caused the Debian Bug report #1035936,
regarding maradns: CVE-2023-31137
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1035936: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1035936
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: maradns
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for maradns.

CVE-2023-31137[0]:
| MaraDNS is open-source software that implements the Domain Name System
| (DNS). In version 3.5.0024 and prior, a remotely exploitable integer
| underflow vulnerability in the DNS packet decompression function
| allows an attacker to cause a Denial of Service by triggering an
| abnormal program termination. The vulnerability exists in the
| `decomp_get_rddata` function within the `Decompress.c` file. When
| handling a DNS packet with an Answer RR of qtype 16 (TXT record) and
| any qclass, if the `rdlength` is smaller than `rdata`, the result of
| the line `Decompress.c:886` is a negative number `len = rdlength -
| total;`. This value is then passed to the `decomp_append_bytes`
| function without proper validation, causing the program to attempt to
| allocate a massive chunk of memory that is impossible to allocate.
| Consequently, the program exits with an error code of 64, causing a
| Denial of Service. One proposed fix for this vulnerability is to patch
| `Decompress.c:887` by breaking `if(len &lt;= 0)`, which has been
| incorporated in version 3.5.0036 via commit
| bab062bde40b2ae8a91eecd522e84d8b993bab58.

https://github.com/samboy/MaraDNS/commit/bab062bde40b2ae8a91eecd522e84d8b993bab58
https://github.com/samboy/MaraDNS/security/advisories/GHSA-58m7-826v-9c3c


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-31137
    https://www.cve.org/CVERecord?id=CVE-2023-31137

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: maradns
Source-Version: 2.0.13-1.5
Done: Aron Xu <[email protected]>

We believe that the bug you reported is fixed in the latest version of
maradns, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aron Xu <[email protected]> (supplier of updated maradns package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 29 Oct 2023 18:14:50 +0800
Source: maradns
Architecture: source
Version: 2.0.13-1.5
Distribution: unstable
Urgency: high
Maintainer: Dariusz Dwornikowski <[email protected]>
Changed-By: Aron Xu <[email protected]>
Closes: 1033252 1035936
Changes:
 maradns (2.0.13-1.5) unstable; urgency=high
 .
   * Non-maintainer upload by the Security Team, patches are from
     Bastien Roucariès of LTS team.
   * CVE-2023-31137: integer underflow in the DNS packet decompression
     (Closes: #1035936).
   * CVE-2022-30256: revoked and expired domains remain resolvable for
     a long time (Closes: #1033252).
Checksums-Sha1:
 e4e8ca1f5c605119884e26e30e58d3857eead7d0 1761 maradns_2.0.13-1.5.dsc
 565fab4c0ff2882e3acaa25490141c2ad337d88e 48204 maradns_2.0.13-1.5.debian.tar.xz
 fcf773db1faec1407aa9b0a35db50091ffbb0c3b 6370 
maradns_2.0.13-1.5_source.buildinfo
Checksums-Sha256:
 a4a27818fa6440856db9315e9af994bbb75b6082a877264d0a6b4c5d42ba7877 1761 
maradns_2.0.13-1.5.dsc
 117e72046c205e86f1b62ae0fce9cf43348209f96c7ff528e8c8b70e68a697e6 48204 
maradns_2.0.13-1.5.debian.tar.xz
 0a11cd7f69b3b5f8a2cca947b50b257ffb3155e2618e7f01cf5cf11cb1364a9a 6370 
maradns_2.0.13-1.5_source.buildinfo
Files:
 941e56123943c63bb4ea300e49e8ced3 1761 net extra maradns_2.0.13-1.5.dsc
 368a8b68fc2f5d87a76f2328d3695011 48204 net extra 
maradns_2.0.13-1.5.debian.tar.xz
 3712f2335f5ba016ed9694fbce4f3b05 6370 net extra 
maradns_2.0.13-1.5_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEhhz+aYQl/Bp4OTA7O1LKKgqv2VQFAmU+NZUACgkQO1LKKgqv
2VSZeQf9Gw6Okk85qmPdhy4j2fRYxzDHW8m6hvaH+Vqj4sAPuJprt/IqvUPaOqvh
AgcJ2J5fT5rQUNdkVeVsAcWyj539GV1LbJbj3z96dr+dGhYzn1dV5PpXnh1yDAVP
hQRtf9gBZkAIE9IT5od4i4eP5w61q/f6Z5ZpwIiOIzeOR9DSMPDGMFPM2Lc4bwjn
10aeCF5vmfm6IKdi6+PnUhxPgkG2pASqGDT0Q5iRb+87X0sGVO4Oi6n2Vg2PKIgo
ZfNxqVRT7JxiDc3cNr2MUTau4wVOpHIBNNVbi8pjc79wzjN1Nkfo58ahvuFDVqQP
uuW/P7Ls0rg/tyJ4grmL0Gm5PggkAg==
=Exbc
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to