Vulnerability Note VU#697164
BIND vulnerable to an INSIST failure via sending of multiple recursive queries
Overview
A vulnerability in the BIND name server could allow a remote attacker to cause a denial of service against an affected system.
Description
The Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS) implementation from Internet Systems Consortium (ISC). A flaw exists in the way that some versions of BIND handle recursive queries. It is possible for a remote attacker to trigger an INSIST failure by sending enough recursive queries that the response to the query arrives after all the clients looking for the response have left the recursion queue. This vulnerability affects BIND 9.3.x versions 9.3.0, 9.3.1, 9.3.2, 9.3.3b, and 9.3.3rc1, and BIND 9.4.x versions 9.4.0a1, 9.4.0a2, 9.4.0a3, 9.4.0a4, 9.4.0a5, 9.4.0a6, and 9.4.0b1. |
Impact
A remote attacker may be able to cause the name server daemon to crash, thereby causing a denial of service for DNS operations. |
Solution
Apply a patch from the vendor |
Restrict Access |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Debian GNU/Linux | Affected | 23 Aug 2006 | 11 Sep 2006 |
| F5 Networks, Inc. | Affected | 23 Aug 2006 | 07 Sep 2006 |
| FreeBSD, Inc. | Affected | 23 Aug 2006 | 07 Sep 2006 |
| Gentoo Linux | Affected | 23 Aug 2006 | 02 Oct 2006 |
| Internet Software Consortium | Affected | 03 Jul 2006 | 06 Sep 2006 |
| Mandriva, Inc. | Affected | 23 Aug 2006 | 11 Sep 2006 |
| NetBSD | Affected | 23 Aug 2006 | 02 Oct 2006 |
| OpenBSD | Affected | 23 Aug 2006 | 07 Sep 2006 |
| OpenPKG | Affected | - | 07 Sep 2006 |
| Openwall GNU/*/Linux | Affected | 23 Aug 2006 | 11 Sep 2006 |
| rPath | Affected | - | 25 Sep 2006 |
| Slackware Linux Inc. | Affected | 23 Aug 2006 | 02 Oct 2006 |
| Trustix Secure Linux | Affected | 23 Aug 2006 | 02 Oct 2006 |
| Ubuntu | Affected | 23 Aug 2006 | 07 Sep 2006 |
| Hitachi | Not Affected | 23 Aug 2006 | 05 Sep 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=en
- http://jvn.jp/cert/JVNVU%23697164/index.html
- http://secunia.com/advisories/21752/
- http://secunia.com/advisories/21816/
Credit
Thanks to Joao Damas of the Internet Software Consortium for reporting this vulnerability.
This document was written by Chad R Dougherty.
Other Information
- CVE IDs: CVE-2006-4096
- Date Public: 05 Sep 2006
- Date First Published: 05 Sep 2006
- Date Last Updated: 02 Oct 2006
- Severity Metric: 5.67
- Document Revision: 13
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.