SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#360341

BIND 9 DNSSEC validation code could cause fake NXDOMAIN responses

Overview

A vulnerability exists in the BIND 9 DNSSEC validation code that could be used by an attacker to generate fake NXDOMAIN responses.

I. Description

BIND 9 contains a vulnerability in DNSSEC validation code. According to ISC:

There was an error in the DNSSEC NSEC/NSEC3 validation code that could cause bogus NXDOMAIN responses (that is, NXDOMAIN responses for records proven by NSEC or NSEC3 to exist) to be cached as if they had validated correctly, so that future queries to the resolver would return the bogus NXDOMAIN with the AD flag set.

This issue affects BIND versions 9.0.x, 9.1.x, 9.2.x, 9.3.x, 9.4.0 -> 9.4.3-P4, 9.5.0 -> 9.5.2-P1, 9.6.0 -> 9.6.1-P2

II. Impact

An attacker may be able to add fake NXDOMAIN records to a resolver's cache.

III. Solution

Upgrade BIND to version 9.4.3-P5, 9.5.2-P2 or 9.6.1-P3.

Systems Affected

VendorStatusDate NotifiedDate Updated
Alcatel-LucentUnknown2010-01-142010-01-14
Apple Inc.Unknown2010-01-142010-01-14
BlueCat Networks, Inc.Unknown2010-01-142010-01-14
Check Point Software TechnologiesUnknown2010-01-142010-01-14
Conectiva Inc.Unknown2010-01-142010-01-14
Cray Inc.Unknown2010-01-142010-01-14
Debian GNU/LinuxUnknown2010-01-142010-01-14
DragonFly BSD ProjectUnknown2010-01-142010-01-14
EMC CorporationUnknown2010-01-142010-01-14
Engarde Secure LinuxUnknown2010-01-142010-01-14
EricssonUnknown2010-01-142010-01-14
F5 Networks, Inc.Unknown2010-01-142010-01-14
Fedora ProjectVulnerable2010-01-142010-01-27
FreeBSD ProjectUnknown2010-01-142010-01-14
FujitsuUnknown2010-01-142010-01-14
Gentoo LinuxUnknown2010-01-142010-01-14
Gnu ADNSUnknown2010-01-142010-01-14
GNU glibcUnknown2010-01-142010-01-14
Hewlett-Packard CompanyUnknown2010-01-142010-01-14
HitachiUnknown2010-01-142010-01-14
IBM CorporationUnknown2010-01-142010-01-14
IBM Corporation (zseries)Unknown2010-01-142010-01-14
IBM eServerUnknown2010-01-142010-01-14
InfobloxUnknown2010-01-142010-01-14
Internet Systems ConsortiumVulnerable2010-01-142010-01-19
Juniper Networks, Inc.Unknown2010-01-142010-01-14
Mandriva S. A.Unknown2010-01-142010-01-14
McAfeeUnknown2010-01-142010-01-14
Men & MiceUnknown2010-01-142010-01-14
Microsoft CorporationUnknown2010-01-142010-01-14
MontaVista Software, Inc.Unknown2010-01-142010-01-14
NEC CorporationUnknown2010-01-142010-01-14
NetBSDUnknown2010-01-142010-01-14
NokiaUnknown2010-01-142010-01-14
NominumUnknown2010-01-142010-01-14
Nortel Networks, Inc.Unknown2010-01-142010-01-14
Novell, Inc.Unknown2010-01-142010-01-14
OpenBSDUnknown2010-01-142010-01-14
Openwall GNU/*/LinuxUnknown2010-01-142010-01-14
QNX Software Systems Inc.Unknown2010-01-142010-01-14
Red Hat, Inc.Vulnerable2010-01-142010-01-27
SafeNetUnknown2010-01-142010-01-14
ShadowsupportUnknown2010-01-142010-01-14
Silicon Graphics, Inc.Unknown2010-01-142010-01-14
Slackware Linux Inc.Unknown2010-01-142010-01-14
Sony CorporationUnknown2010-01-142010-01-14
Sun Microsystems, Inc.Vulnerable2010-01-142010-01-27
SUSE LinuxUnknown2010-01-142010-01-14
The SCO GroupVulnerable2010-01-142010-01-27
TurbolinuxUnknown2010-01-142010-01-14
UbuntuVulnerable2010-01-142010-01-27
UnisysUnknown2010-01-142010-01-14
Wind River Systems, Inc.Unknown2010-01-142010-01-14

References

https://www.isc.org/advisories/CVE-2010-0097

Credit

This issue was reported by ISC.

This document was written by David Warren.

Other Information

Date Public:2010-01-19
Date First Published:2010-01-19
Date Last Updated:2010-01-27
CERT Advisory: 
CVE-ID(s):CVE-2010-0097
NVD-ID(s):CVE-2010-0097
US-CERT Technical Alerts: 
Metric:0.00
Document Revision:12

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2010 by US-CERT, a government organization
Disclaimers and copyright information
Get a PDF Reader