SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#718460

ISC BIND denial of service vulnerability

Overview

A vulnerability in the BIND name server could allow a remote attacker to cause a denial of service against an affected system.

I. Description

The Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS) implementation from Internet Systems Consortium (ISC).


BIND version 9.4.0 contains a vulnerability in the way that the query_addsoa() function is called. A remote attacker with the ability to send a specific sequence of queries to a vulnerable system can cause the nameserver to exit. Note that recursion must be enabled on the nameserver for this vulnerability to be exposed.

II. Impact

A remote attacker may be able to cause the name server daemon to exit prematurely, thereby causing a denial of service for DNS operations.

III. Solution

Upgrade


Users who compile their own copies of the affected version of BIND (9.4.0) from the original ISC source code are encouraged to upgrade to BIND version 9.4.1 (or later), which includes a patch for this issue.

Workarounds

Disable Recursion
Users, particularly those who are not able to upgrade, are encouraged to disable recursion ('recursion no;' set in named.conf) if it is not required by their configuration.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Not Vulnerable15-May-2007
BlueCat Networks, Inc.Unknown2-May-2007
Check Point Software TechnologiesUnknown2-May-2007
Conectiva Inc.Unknown2-May-2007
Cray Inc.Unknown2-May-2007
Debian GNU/LinuxUnknown2-May-2007
EMC, Inc. (formerly Data General Corporation)Unknown2-May-2007
Engarde Secure LinuxUnknown2-May-2007
F5 Networks, Inc.Unknown2-May-2007
Fedora ProjectUnknown2-May-2007
FreeBSD, Inc.Unknown2-May-2007
FujitsuUnknown2-May-2007
Gentoo LinuxUnknown2-May-2007
Gnu ADNSUnknown2-May-2007
GNU glibcUnknown2-May-2007
Hewlett-Packard CompanyUnknown2-May-2007
HitachiUnknown2-May-2007
IBM CorporationUnknown2-May-2007
IBM Corporation (zseries)Unknown2-May-2007
IBM eServerUnknown2-May-2007
Immunix Communications, Inc.Unknown2-May-2007
InfobloxUnknown2-May-2007
Ingrian Networks, Inc.Unknown2-May-2007
Internet Software ConsortiumVulnerable2-May-2007
Juniper Networks, Inc.Unknown2-May-2007
Lucent TechnologiesUnknown2-May-2007
Mandriva, Inc.Vulnerable15-May-2007
Men & MiceUnknown2-May-2007
Metasolv Software, Inc.Unknown2-May-2007
Microsoft CorporationUnknown2-May-2007
MontaVista Software, Inc.Unknown2-May-2007
NEC CorporationUnknown2-May-2007
NetBSDVulnerable3-Jul-2007
NokiaUnknown2-May-2007
Nortel Networks, Inc.Unknown2-May-2007
Novell, Inc.Not Vulnerable9-May-2007
OpenBSDUnknown2-May-2007
Openwall GNU/*/LinuxNot Vulnerable9-May-2007
QNX, Software Systems, Inc.Unknown2-May-2007
Red Hat, Inc.Unknown2-May-2007
ShadowsupportUnknown2-May-2007
Silicon Graphics, Inc.Unknown2-May-2007
Slackware Linux Inc.Not Vulnerable3-May-2007
Sony CorporationUnknown2-May-2007
Sun Microsystems, Inc.Not Vulnerable15-May-2007
SUSE LinuxUnknown2-May-2007
The SCO GroupUnknown2-May-2007
Trustix Secure LinuxUnknown2-May-2007
TurbolinuxUnknown2-May-2007
UbuntuNot Vulnerable3-May-2007
UnisysUnknown2-May-2007
Wind River Systems, Inc.Unknown2-May-2007

References


http://www.isc.org/sw/bind/bind-security.php
http://secunia.com/advisories/25070/

Credit

Thanks to Mark Andrews of the Internet Systems Consortium (ISC) for reporting this vulnerability.

This document was written by Chad R Dougherty.

Other Information

Date Public:2007-05-01
Date First Published:2007-05-03
Date Last Updated:2007-07-03
CERT Advisory: 
CVE-ID(s):CVE-2007-2241
NVD-ID(s):CVE-2007-2241
US-CERT Technical Alerts: 
Metric:6.90
Document Revision:13

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader