SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#187297

ISC BIND does not correctly set default access controls

Overview

ISC (Internet Systems Consortiuim) BIND fails to properly set default access control lists. This may allow unauthorized users to make recursive querries and querry the cache.

I. Description

From the ISC BIND security page:

    The default access control lists (acls) are not being correctly set. If not set anyone can make recursive queries and/or query the cache contents.


Note that the BIND advisory lists BIND 9.4.0, 9.4.1, 9.5.0a1, 9.5.0a2, 9.5.0a3, 9.5.0a4, and 9.5.0a5 as the versions affected.

II. Impact

A remote, unauthenticated attacker may be able to cause a vulnerable DNS server perform recursion. This could be used to perform denial-of-service attacks. An attacker may also be able to querry the cache.

III. Solution

Upgrade or Patch

This issue is addressed in ISC BIND 9.2.8-P1, BIND 9.3.4-P1, BIND 9.4.1-P1 or BIND 9.5.0a6. Users who obtain BIND from their operating system vendor should see the systems affected portion of this document for a partial list of affected vendors.

Workarounds for administrators of non-publicly accessisble recursive DNS servers

  • Using firewall rules, limit access to the DNS server to authorized networks.
Workarounds for administrators of publicly accessisble recursive DNS servers
  • Rate limiting the number of external recursion requests may mitigate potential abuse of the DNS server.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Unknown27-Jul-2007
Conectiva Inc.Unknown27-Jul-2007
Cray Inc.Unknown27-Jul-2007
Debian GNU/LinuxVulnerable30-Jul-2007
EMC CorporationNot Vulnerable30-Jul-2007
Engarde Secure LinuxUnknown27-Jul-2007
F5 Networks, Inc.Unknown27-Jul-2007
Fedora ProjectUnknown27-Jul-2007
FreeBSD, Inc.Unknown27-Jul-2007
FujitsuUnknown27-Jul-2007
Gentoo LinuxUnknown27-Jul-2007
Hewlett-Packard CompanyUnknown27-Jul-2007
HitachiNot Vulnerable30-Jul-2007
IBM CorporationUnknown27-Jul-2007
Immunix Communications, Inc.Unknown27-Jul-2007
Ingrian Networks, Inc.Unknown27-Jul-2007
Internet Software ConsortiumVulnerable27-Jul-2007
Juniper Networks, Inc.Unknown27-Jul-2007
Mandriva, Inc.Unknown27-Jul-2007
Microsoft CorporationUnknown27-Jul-2007
MontaVista Software, Inc.Unknown27-Jul-2007
NEC CorporationUnknown27-Jul-2007
NetBSDUnknown27-Jul-2007
Novell, Inc.Unknown27-Jul-2007
OpenBSDUnknown27-Jul-2007
Openwall GNU/*/LinuxNot Vulnerable8-Aug-2007
QNX, Software Systems, Inc.Unknown27-Jul-2007
Red Hat, Inc.Not Vulnerable28-Jul-2007
Silicon Graphics, Inc.Unknown27-Jul-2007
Slackware Linux Inc.Unknown27-Jul-2007
Sony CorporationUnknown27-Jul-2007
Sun Microsystems, Inc.Not Vulnerable3-Aug-2007
SUSE LinuxNot Vulnerable2-Aug-2007
The SCO GroupUnknown27-Jul-2007
Trustix Secure LinuxUnknown27-Jul-2007
TurbolinuxUnknown27-Jul-2007
UbuntuUnknown27-Jul-2007
UnisysUnknown27-Jul-2007
Wind River Systems, Inc.Unknown27-Jul-2007

References


http://www.isc.org/sw/bind/bind-security.php
http://www.netfilter.org/documentation/HOWTO/packet-filtering-HOWTO-7.html

Credit

Thanks to ISC for information that was used in this report.

This document was written by Ryan Giobbi.

Other Information

Date Public:2007-07-24
Date First Published:2007-07-27
Date Last Updated:2008-06-04
CERT Advisory: 
CVE-ID(s):CVE-2007-2925
NVD-ID(s):CVE-2007-2925
US-CERT Technical Alerts: 
Metric:16.98
Document Revision:25

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader