Vulnerability Note VU#252735
ISC BIND generates cryptographically weak DNS query IDs
Overview
ISC (Internet Systems Consortiuim) BIND generates cryptographically weak DNS query IDs which could allow a remote attacker to poison DNS caches.
Description
From the ISC Bind security page: The DNS query id generation is vulnerable to cryptographic analysis which provides a 1 in 8 chance of guessing the next query id for 50% of the query ids. This can be used to perform cache poisoning by an attacker. |
Impact
A remote attacker could predict DNS query IDs and respond with arbitrary answers, thus poisoning DNS caches. |
Solution
Upgrade or Patch
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Debian GNU/Linux | Affected | 26 Jul 2007 | 30 Jul 2007 |
| Fujitsu | Affected | 26 Jul 2007 | 01 Oct 2007 |
| Internet Software Consortium | Affected | - | 27 Jul 2007 |
| Openwall GNU/*/Linux | Affected | 26 Jul 2007 | 08 Aug 2007 |
| Red Hat, Inc. | Affected | 26 Jul 2007 | 28 Jul 2007 |
| Sun Microsystems, Inc. | Affected | 26 Jul 2007 | 03 Aug 2007 |
| SUSE Linux | Affected | 26 Jul 2007 | 03 Aug 2007 |
| Ubuntu | Affected | 26 Jul 2007 | 06 Aug 2008 |
| EMC Corporation | Not Affected | 26 Jul 2007 | 30 Jul 2007 |
| Hitachi | Not Affected | 26 Jul 2007 | 30 Jul 2007 |
| Apple Computer, Inc. | Unknown | 26 Jul 2007 | 26 Jul 2007 |
| Conectiva Inc. | Unknown | 26 Jul 2007 | 26 Jul 2007 |
| Cray Inc. | Unknown | 26 Jul 2007 | 26 Jul 2007 |
| Engarde Secure Linux | Unknown | 26 Jul 2007 | 26 Jul 2007 |
| F5 Networks, Inc. | Unknown | 26 Jul 2007 | 26 Jul 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.isc.org/sw/bind/bind-security.php
- http://www.trusteer.com/docs/bind9dns.html
- http://jvn.jp/cert/JVNVU%23252735/index.html
- http://secunia.com/advisories/26195/
- http://www.milw0rm.com/exploits/4266
- http://docs.info.apple.com/article.html?artnum=307041
Credit
This vulnerability was reported by ISC who credit Amit Klein from Trusteer.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: CVE-2007-2926
- Date Public: 24 Jul 2007
- Date First Published: 27 Jul 2007
- Date Last Updated: 06 Aug 2008
- Severity Metric: 3.83
- Document Revision: 27
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.