Vulnerability Note VU#16532
BIND T_NXT record processing may cause buffer overflow
Overview
A vulnerability in BIND, repaired in verison 8.2.2p5, allows remote attackers to execute code with the privileges of the process running named. This vulnerability was widely exploited from November 1999 to December 2000.
Description
There is a buffer overflow in the processing of NXT records in the routine rrextract, part of the file ns_resp.c. Specifically, in vulnerable versions of BIND, there is a section of code which reads: An exploit for this vulnerability is publicly available . |
Impact
Remote user may gain default process access of local nameserver, usually root |
Solution
Upgrade to the latest version of BIND. |
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Compaq Computer Corporation | Unknown | - | 20 Apr 2002 |
| Data General | Unknown | - | 20 Apr 2002 |
| Fujitsu | Not Vulnerable | - | 20 Apr 2002 |
| Sun Microsystems, Inc. | Not Vulnerable | - | 03 Feb 2006 |
| The SCO Group (SCO Unix) | Vulnerable | - | 03 Feb 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.cert.org/advisories/CA-2000-03.html
- http://www.cert.org/summaries/CS-2000-02.html
- http://www.cert.org/summaries/CS-2000-01.html
- http://www.cert.org/summaries/CS-99-04.html
- http://www.isc.org/products/BIND/bind-security-19991108.html
- http://www.redhat.com/support/errata/RHSA1999054-01.html
- http://www.debian.org/security/1999/19991116
- ftp://ftp.sco.com/SSE/sse033.ltr
- http://www.securityfocus.com/vdb/bottom.html?vid=788
Credit
Our thanks to ISC for assistance in understanding this vulnerability.
This document was written by Shawn V Hernan.
Other Information
- CVE IDs: CVE-1999-0833
- CERT Advisory: CA-1999-14
- Date Public: 10 Nov 99
- Date First Published: 28 Jan 2001
- Date Last Updated: 03 Feb 2006
- Severity Metric: 108.16
- Document Revision: 7
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify