CERT home
vulnerabilities & fixesevaluations & practicesresearch & analysistraining & education
homesearchFAQsite indexcontact
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

Vulnerability Note VU#725188

ISC BIND 9 vulnerable to denial of service via dynamic update request

Overview

ISC BIND 9 contains a vulnerability that may allow a remote, unauthenticated attacker to create a denial-of-service condition.

I. Description

The Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS) implementation from Internet Systems Consortium (ISC). It includes support for dynamic DNS updates as specified in IETF RFC 2136. BIND 9 can crash when processing a specially-crafted dynamic update packet.

ISC notes that this vulnerability affects all servers that are masters for one or more zones and is not limited to those that are configured to allow dynamic updates. ISC also indicates that the attack packet has to be constructed for a zone for which the target system is configured as a master; launching the attack against slave zones does not trigger the vulnerability.

II. Impact

By sending a specially-crafted dynamic update packet to a BIND 9 server, a remote, unauthenticated attacker can cause a denial of service by causing BIND to crash.

III. Solution

Apply an update

Users who obtain BIND from a third-party vendor, such as their operating system vendor, should see the systems affected portion of this document for a partial list of affected vendors.

This vulnerability is addressed in ISC BIND versions 9.4.3-P3, 9.5.1-P3, and BIND 9.6.1-P1. Users of BIND from the original source distribution should upgrade to one of these versions, as appropriate.

See also https://www.isc.org/node/474.

Systems Affected

VendorStatusDate Updated
Alcatel-LucentUnknown2009-07-282009-07-28
Apple Inc.Vulnerable2009-07-282009-08-17
BlueCat Networks, Inc.Vulnerable2009-07-282009-07-30
Check Point Software TechnologiesUnknown2009-07-282009-07-28
Conectiva Inc.Unknown2009-07-282009-07-28
Cray Inc.Unknown2009-07-282009-07-28
Debian GNU/LinuxVulnerable2009-07-282009-08-03
DragonFly BSD ProjectUnknown2009-07-282009-07-28
EMC CorporationUnknown2009-07-282009-07-28
Engarde Secure LinuxUnknown2009-07-282009-07-28
EricssonUnknown2009-07-282009-07-28
F5 Networks, Inc.Vulnerable2009-07-282009-07-31
Fedora ProjectUnknown2009-07-282009-07-28
FreeBSD, Inc.Vulnerable2009-07-282009-07-30
FujitsuUnknown2009-07-282009-07-28
Gentoo LinuxUnknown2009-07-282009-07-28
Gnu ADNSUnknown2009-07-282009-07-28
GNU glibcUnknown2009-07-282009-07-28
Hewlett-Packard CompanyVulnerable2009-07-282009-08-26
HitachiUnknown2009-07-282009-07-28
IBM CorporationUnknown2009-07-282009-07-28
IBM eServerUnknown2009-07-282009-07-28
InfobloxVulnerable2009-07-282009-07-30
Internet Systems ConsortiumVulnerable2009-07-282009-07-28
Juniper Networks, Inc.Unknown2009-07-282009-07-28
Mandriva S. A.Unknown2009-07-282009-07-28
McAfeeUnknown2009-07-282009-07-28
Men & MiceUnknown2009-07-282009-07-28
Metasolv Software, Inc.Unknown2009-07-282009-07-28
Microsoft CorporationUnknown2009-08-032009-08-03
MontaVista Software, Inc.Unknown2009-07-282009-07-28
NEC CorporationUnknown2009-07-282009-07-28
NetBSDUnknown2009-07-282009-07-28
NixuVulnerable2009-07-282009-07-30
NokiaUnknown2009-07-282009-07-28
NominumNot Vulnerable2009-07-282009-07-30
Nortel Networks, Inc.Unknown2009-07-282009-07-28
Novell, Inc.Unknown2009-07-282009-07-28
OpenBSDVulnerable2009-07-282009-07-30
Openwall GNU/*/LinuxUnknown2009-07-282009-07-28
QNX, Software Systems, Inc.Unknown2009-07-282009-07-28
Red Hat, Inc.Vulnerable2009-07-282009-07-30
SafeNetUnknown2009-07-282009-07-28
ShadowsupportUnknown2009-07-282009-07-28
Silicon Graphics, Inc.Unknown2009-07-282009-07-28
Slackware Linux Inc.Unknown2009-07-282009-07-28
Sony CorporationUnknown2009-07-282009-07-28
Sun Microsystems, Inc.Vulnerable2009-07-282009-07-30
SUSE LinuxVulnerable2009-07-282009-07-31
The SCO GroupUnknown2009-07-282009-07-28
TurbolinuxUnknown2009-07-282009-07-28
UbuntuVulnerable2009-07-282009-07-29
UnisysUnknown2009-07-282009-07-28
Wind River Systems, Inc.Unknown2009-07-282009-07-28

References


https://www.isc.org/node/474
http://tools.ietf.org/html/rfc2136
http://oldwww.isc.org/sw/bind/view?release=9.4.3-P3&noframes=1
http://oldwww.isc.org/sw/bind/view?release=9.5.1-P3&noframes=1
http://oldwww.isc.org/sw/bind/view?release=9.6.1-P1&noframes=1
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975

Credit

Thanks to ISC for reporting this vulnerability.

This document was written by Will Dormann and Chad Dougherty.

Other Information

Date Public07/28/2009
Date First Published07/28/2009 03:01:33 PM
Date Last Updated08/27/2009
CERT Advisory 
CVE NameCVE-2009-0696
Metric26.32
Document Revision32

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Copyright 2009 Carnegie Mellon University