Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-11 Thread Yves-Alexis Perez
On jeu., 2014-12-11 at 09:35 +0100, Ansgar Burchardt wrote: > > > > Ansgar: will it not be an issue to have both debian.tar.{gz,xz} in the > > archive? > > No, the second .debian.tar.* is not kept: it's referenced by the > .changes so dak verifies that it's included in the upload, but then gets >

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-11 Thread Ansgar Burchardt
Hi, Yves-Alexis Perez writes: > I guess Ansgar put the debian.tar.xz at the right place, the processing > was successful in the end. > > Ansgar: will it not be an issue to have both debian.tar.{gz,xz} in the > archive? No, the second .debian.tar.* is not kept: it's referenced by the .changes so

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-11 Thread Yves-Alexis Perez
On mer., 2014-12-10 at 17:38 -0500, Robert Edmonds wrote: > Salvatore Bonaccorso wrote: > > [23:26] < ansgar> As the .dsc looks right (it only has one), the uploader > > can just fix the .changes and upload to ftp-master. Or give me the missing > > .debian.tar.*. > > > > Can you do one of the b

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-10 Thread Robert Edmonds
Salvatore Bonaccorso wrote: > [23:26] < ansgar> As the .dsc looks right (it only has one), the uploader can > just fix the .changes and upload to ftp-master. Or give me the missing > .debian.tar.*. > > Can you do one of the both approaches? Hi, The .debian.tar.* files are available here:

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-10 Thread Salvatore Bonaccorso
Hi, On Wed, Dec 10, 2014 at 11:20:36PM +0100, Kurt Roeckx wrote: > On Wed, Dec 10, 2014 at 10:59:20PM +0100, Yves-Alexis Perez wrote: > > > > [WB-team: we have an issue with the unbound amd64 build for DSA 3097-1, > > so I'm adding you to the loop, see below] > > > > On mer., 2014-12-10 at 16:46

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-10 Thread Kurt Roeckx
On Wed, Dec 10, 2014 at 10:59:20PM +0100, Yves-Alexis Perez wrote: > > [WB-team: we have an issue with the unbound amd64 build for DSA 3097-1, > so I'm adding you to the loop, see below] > > On mer., 2014-12-10 at 16:46 -0500, Robert Edmonds wrote: > > Yves-Alexis Perez wrote: > > > Thanks. Altho

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-10 Thread Yves-Alexis Perez
[WB-team: we have an issue with the unbound amd64 build for DSA 3097-1, so I'm adding you to the loop, see below] On mer., 2014-12-10 at 16:46 -0500, Robert Edmonds wrote: > Yves-Alexis Perez wrote: > > Thanks. Although it seems your _multi.changes might have issue. How > > exactly did you made i

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-10 Thread Robert Edmonds
Yves-Alexis Perez wrote: > Thanks. Although it seems your _multi.changes might have issue. How > exactly did you made it? It apparently references twice the debian > changes: > > b05bf69385554dddaa22629327ac647c384c1585 15413 > unbound_1.4.17-3+deb7u2.debian.tar.gz > d4addd58c211ff20d707e52d961be

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-10 Thread Yves-Alexis Perez
On mer., 2014-12-10 at 10:40 -0500, Robert Edmonds wrote: > Yves-Alexis Perez wrote: > > On mar., 2014-12-09 at 18:46 -0500, Robert Edmonds wrote: > > > Yves-Alexis Perez wrote: > > > > For Wheezy you need to build with -sa (since it's the first security > > > > upload) and target wheezy-security d

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-10 Thread Robert Edmonds
Yves-Alexis Perez wrote: > On mar., 2014-12-09 at 18:46 -0500, Robert Edmonds wrote: > > Yves-Alexis Perez wrote: > > > For Wheezy you need to build with -sa (since it's the first security > > > upload) and target wheezy-security distribution. Then you send us the > > > debdiff so we can have a qui

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-10 Thread Yves-Alexis Perez
On mar., 2014-12-09 at 18:46 -0500, Robert Edmonds wrote: > Yves-Alexis Perez wrote: > > For Wheezy you need to build with -sa (since it's the first security > > upload) and target wheezy-security distribution. Then you send us the > > debdiff so we can have a quick check, and after our ACK you can

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-09 Thread Robert Edmonds
Yves-Alexis Perez wrote: > For Wheezy you need to build with -sa (since it's the first security > upload) and target wheezy-security distribution. Then you send us the > debdiff so we can have a quick check, and after our ACK you can upload > to security-master and we release the DSA. OK, see atta

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-09 Thread Robert Edmonds
Yves-Alexis Perez wrote: > Hi, > > as you may already know, a vulnerability in several recursive DNS > implementations (bind, pdns-recursor and unbound, maybe others) has been > found by a research. > > For unbound, it has been assigned CVE-2014-8602 and more information can > be found on the mai

Bug#772622: CVE-2014-8602: denial of service with endless delegations

2014-12-09 Thread Yves-Alexis Perez
Source: unbound Severity: grave Tags: security Justification: user security hole Hi, as you may already know, a vulnerability in several recursive DNS implementations (bind, pdns-recursor and unbound, maybe others) has been found by a research. For unbound, it has been assigned CVE-2014-8602 and