Vulnerability Note VU#715973
ISC BIND 8.2.2-P6 vulnerable to DoS via compressed zone transfer, aka the "zxfr bug"
Overview
There is a denial-of-service vulnerability in several versions of the Internet Software Consortium's (ISC) BIND software. This vulnerability is referred to by the ISC as the "zxfr bug." It affects ISC BIND version 8.2.2, patch levels 1 through 6.
Description
Using this vulnerability, attackers on sites that are permitted to request zone transfers can force the name service daemon (named) running on vulnerable DNS servers to crash, disrupting name resolution service until the named daemon is restarted. The preconditions for this attack to succeed are as follows:
The time between the attack and the crash of named may vary from system to system. This vulnerability has been discussed in public forums. The ISC has confirmed that all platforms running version 8.2.2 of the BIND software prior to patch level 7 are vulnerable to this attack. |
Impact
A remote attacker can use malicious zone transfers to crash vulnerable BIND servers, resulting in a denial-of-service condition that disables name resolution service. |
Solution
Apply a patch from your vendor |
If it is not possible to immediately upgrade systems affected by the "zxfr bug", the ISC recommends that users block zone transfers from untrusted hosts. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Caldera | Affected | 12 Nov 2000 | 16 May 2001 |
| Compaq Computer Corporation | Affected | 12 Nov 2000 | 16 May 2001 |
| Conectiva | Affected | - | 16 May 2001 |
| Debian | Affected | - | 16 May 2001 |
| Hewlett Packard | Affected | 12 Nov 2000 | 11 May 2001 |
| IBM | Affected | 12 Nov 2000 | 11 May 2001 |
| ISC | Affected | - | 13 Nov 2000 |
| MandrakeSoft | Affected | - | 13 Nov 2000 |
| NetBSD | Affected | 12 Nov 2000 | 13 Nov 2000 |
| RedHat | Affected | 12 Nov 2000 | 13 Nov 2000 |
| Slackware | Affected | - | 13 Nov 2000 |
| SuSE | Affected | 16 Nov 2000 | 11 May 2001 |
| Trustix | Affected | 16 Nov 2000 | 16 May 2001 |
| FreeBSD | Not Affected | 12 Nov 2000 | 11 May 2001 |
| Fujitsu | Not Affected | 12 Nov 2000 | 11 May 2001 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.securityfocus.com/bid/1923
- http://www.isc.org/products/BIND/bind8.html
- http://www.isc.org/products/BIND/bind-security.html
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=20546
- http://www.securityfocus.com/archive/82/144170
Credit
The CERT Coordination Center thanks Mark Andrews, David Conrad, and Paul Vixie of the ISC for developing a solution and assisting in the preparation of this document. We also thank Olaf Kirch for helping us to understand the exact nature of the "zxfr bug" vulnerability.
This document was written by Jeffrey S. Havrilla and Jeffrey P. Lanza.
Other Information
- CVE IDs: CVE-2000-0887
- CERT Advisory: CA-2000-20
- Date Public: 07 Nov 2000
- Date First Published: 10 Nov 2000
- Date Last Updated: 08 Aug 2001
- Severity Metric: 33.08
- Document Revision: 33
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.