Vulnerability Note VU#327633
BIND 8.4.4 and 8.4.5 vulnerable to buffer overflow in q_usedns
Overview
A vulnerability in the BIND name server could allow a remote attacker to cause a denial of service against an affected system.
Description
The Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS) implementation from Internet Systems Consortium (ISC). A buffer overflow error exists in the handling of the q_usedns array used by the server to track nameservers and addresses that have been queried. This vulnerability only affects BIND versions 8.4.4 and 8.4.5. |
Impact
A remote attacker may be able to cause the name server daemon to crash, thereby causing a denial of service for DNS operations. |
Solution
Apply a patch from the vendor Patches have been released in response to this issue. Please see the Systems Affected section of this document. |
Workarounds
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Debian | Affected | 17 Jan 2005 | 25 Jan 2005 |
| ISC | Affected | - | 25 Jan 2005 |
| Apple Computer Inc. | Not Affected | 17 Jan 2005 | 18 Mar 2005 |
| Check Point | Not Affected | 17 Jan 2005 | 24 Jan 2005 |
| Hitachi | Not Affected | 17 Jan 2005 | 20 Jan 2005 |
| IBM | Not Affected | 17 Jan 2005 | 24 Jan 2005 |
| Juniper Networks | Not Affected | 17 Jan 2005 | 24 Jan 2005 |
| MandrakeSoft | Not Affected | 17 Jan 2005 | 31 Jan 2005 |
| NEC Corporation | Not Affected | 17 Jan 2005 | 18 Mar 2005 |
| Red Hat Inc. | Not Affected | 17 Jan 2005 | 18 Jan 2005 |
| Sun Microsystems Inc. | Not Affected | 17 Jan 2005 | 24 Jan 2005 |
| Adns | Unknown | 17 Jan 2005 | 17 Jan 2005 |
| BlueCat Networks | Unknown | 17 Jan 2005 | 17 Jan 2005 |
| Conectiva | Unknown | 17 Jan 2005 | 17 Jan 2005 |
| Cray Inc. | Unknown | 17 Jan 2005 | 17 Jan 2005 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.isc.org/sw/bind/bind-security.php
- http://www.niscc.gov.uk/niscc/docs/al-20050125-00059.html?lang=en
Credit
Thanks to Joao Damas of the Internet Systems Consortium for reporting this vulnerability.
This document was written by Chad Dougherty based on information provided by ISC.
Other Information
- CVE IDs: CAN-2005-0033
- Date Public: 25 Jan 2005
- Date First Published: 25 Jan 2005
- Date Last Updated: 18 Mar 2005
- Severity Metric: 1.91
- Document Revision: 21
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.