SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#252735

ISC BIND generates cryptographically weak DNS query IDs

Overview

ISC (Internet Systems Consortiuim) BIND generates cryptographically weak DNS query IDs which could allow a remote attacker to poison DNS caches.

I. Description

From the ISC Bind security page:

    The DNS query id generation is vulnerable to cryptographic analysis which provides a 1 in 8 chance of guessing the next query id for 50% of the query ids. This can be used to perform cache poisoning by an attacker.

    This bug only affects outgoing queries, generated by BIND 9 to answer questions as a resolver, or when it is looking up data for internal uses, such as when sending NOTIFYs to slave name servers.

    All users are encouraged to upgrade.

II. Impact

A remote attacker could predict DNS query IDs and respond with arbitrary answers, thus poisoning DNS caches.

III. Solution

Upgrade or Patch


This issue is addressed in ISC BIND 9.2.8-P1, BIND 9.3.4-P1, BIND 9.4.1-P1 or BIND 9.5.0a6. Users who obtain BIND from their operating system vendor should see the systems affected portion of this document for a partial list of affected vendors.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Unknown26-Jul-2007
Conectiva Inc.Unknown26-Jul-2007
Cray Inc.Unknown26-Jul-2007
Debian GNU/LinuxVulnerable30-Jul-2007
EMC CorporationNot Vulnerable30-Jul-2007
Engarde Secure LinuxUnknown26-Jul-2007
F5 Networks, Inc.Unknown26-Jul-2007
Fedora ProjectUnknown26-Jul-2007
FreeBSD, Inc.Unknown26-Jul-2007
FujitsuVulnerable1-Oct-2007
Gentoo LinuxUnknown26-Jul-2007
Hewlett-Packard CompanyUnknown26-Jul-2007
HitachiNot Vulnerable30-Jul-2007
IBM CorporationUnknown26-Jul-2007
IBM Corporation (zseries)Unknown26-Jul-2007
IBM eServerUnknown26-Jul-2007
Immunix Communications, Inc.Unknown26-Jul-2007
Ingrian Networks, Inc.Unknown26-Jul-2007
Internet Software ConsortiumVulnerable27-Jul-2007
Juniper Networks, Inc.Unknown26-Jul-2007
Mandriva, Inc.Unknown26-Jul-2007
Microsoft CorporationUnknown26-Jul-2007
MontaVista Software, Inc.Unknown26-Jul-2007
NEC CorporationUnknown26-Jul-2007
NetBSDUnknown26-Jul-2007
Novell, Inc.Unknown26-Jul-2007
OpenBSDUnknown26-Jul-2007
Openwall GNU/*/LinuxVulnerable8-Aug-2007
QNX, Software Systems, Inc.Unknown26-Jul-2007
Red Hat, Inc.Vulnerable28-Jul-2007
Silicon Graphics, Inc.Unknown26-Jul-2007
Slackware Linux Inc.Unknown26-Jul-2007
Sony CorporationUnknown26-Jul-2007
Sun Microsystems, Inc.Vulnerable3-Aug-2007
SUSE LinuxVulnerable3-Aug-2007
The SCO GroupUnknown26-Jul-2007
Trustix Secure LinuxUnknown26-Jul-2007
TurbolinuxUnknown26-Jul-2007
UbuntuVulnerable6-Aug-2008
UnisysUnknown26-Jul-2007
Wind River Systems, Inc.Unknown26-Jul-2007

References


http://www.isc.org/sw/bind/bind-security.php
http://www.trusteer.com/docs/bind9dns.html
http://jvn.jp/cert/JVNVU%23252735/index.html
http://secunia.com/advisories/26195/
http://www.milw0rm.com/exploits/4266
http://docs.info.apple.com/article.html?artnum=307041

Credit

This vulnerability was reported by ISC who credit Amit Klein from Trusteer.

This document was written by Ryan Giobbi.

Other Information

Date Public:2007-07-24
Date First Published:2007-07-27
Date Last Updated:2008-08-06
CERT Advisory: 
CVE-ID(s):CVE-2007-2926
NVD-ID(s):CVE-2007-2926
US-CERT Technical Alerts: 
Metric:3.83
Document Revision:27

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader