SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#715973

ISC BIND 8.2.2-P6 vulnerable to DoS via compressed zone transfer, aka the "zxfr bug"

Overview

There is a denial-of-service vulnerability in several versions of the Internet Software Consortium's (ISC) BIND software. This vulnerability is referred to by the ISC as the "zxfr bug." It affects ISC BIND version 8.2.2, patch levels 1 through 6.

I. Description

Using this vulnerability, attackers on sites that are permitted to request zone transfers can force the name service daemon (named) running on vulnerable DNS servers to crash, disrupting name resolution service until the named daemon is restarted.

The preconditions for this attack to succeed are as follows:

  • A compressed zone transfer (ZXFR) request must be made from a site allowed to make any zone transfer request (not just ZXFR).
  • A subsequent name service query of an authoritative and non-cached record must be made.

The time between the attack and the crash of named may vary from system to system.

This vulnerability has been discussed in public forums. The ISC has confirmed that all platforms running version 8.2.2 of the BIND software prior to patch level 7 are vulnerable to this attack.

II. Impact

A remote attacker can use malicious zone transfers to crash vulnerable BIND servers, resulting in a denial-of-service condition that disables name resolution service.

III. Solution

Apply a patch from your vendor


To address this vulnerability, the CERT/CC recommends that all users of ISC BIND upgrade to version 8.2.2-P7, which patches both VU#198355 and VU#715973. For information regarding vendor-specific versions of DNS software, please consult the Systems Affected section of this document.

If it is not possible to immediately upgrade systems affected by the "zxfr bug", the ISC recommends that users block zone transfers from untrusted hosts.

Systems Affected

VendorStatusDate NotifiedDate Updated
CalderaVulnerable16-May-2001
Compaq Computer CorporationVulnerable16-May-2001
ConectivaVulnerable16-May-2001
DebianVulnerable16-May-2001
FreeBSDNot Vulnerable11-May-2001
FujitsuNot Vulnerable11-May-2001
Hewlett PackardVulnerable11-May-2001
IBMVulnerable11-May-2001
ImmunixUnknown16-May-2001
ISCVulnerable13-Nov-2000
MandrakeSoftVulnerable13-Nov-2000
MicrosoftNot Vulnerable14-Nov-2000
NetBSDVulnerable13-Nov-2000
RedHatVulnerable13-Nov-2000
SlackwareVulnerable13-Nov-2000
SuSEVulnerable11-May-2001
TrustixVulnerable16-May-2001

References


http://www.securityfocus.com/bid/1923
http://www.isc.org/products/BIND/bind8.html
http://www.isc.org/products/BIND/bind-security.html
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=20546
http://www.securityfocus.com/archive/82/144170

Credit

The CERT Coordination Center thanks Mark Andrews, David Conrad, and Paul Vixie of the ISC for developing a solution and assisting in the preparation of this document. We also thank Olaf Kirch for helping us to understand the exact nature of the "zxfr bug" vulnerability.

This document was written by Jeffrey S. Havrilla and Jeffrey P. Lanza.

Other Information

Date Public:2000-11-07
Date First Published:2000-11-10
Date Last Updated:2001-08-08
CERT Advisory:CA-2000-20
CVE-ID(s):CVE-2000-0887
NVD-ID(s):CVE-2000-0887
US-CERT Technical Alerts: 
Metric:33.08
Document Revision:33

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2000 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader