SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#734644

ISC BIND 8 vulnerable to cache poisoning via negative responses

Overview

The BIND 8 name server contains a cache poisoning vulnerability that allows attackers to conduct denial-of-service attacks on specific target domains.

I. Description

Several versions of the BIND 8 name server are vulnerable to cache poisoning via negative responses. To exploit this vulnerability, an attacker must configure a name server to return authoritative negative responses for a given target domain. Then, the attacker must convince a victim user to query the attacker's maliciously configured name server. When the attacker's name server receives the query, it will reply with an authoritative negative response containing a large TTL (time-to-live) value. If the victim's site runs a vulnerable version of BIND 8, it will cache the negative response and render the target domain unreachable until the TTL expires.

II. Impact

Attackers may conduct denial-of-service attacks on specific target domains by enticing users to query a malicious name server.

III. Solution

Upgrade BIND

The ISC has prepared BIND 8.3.7 and BIND 8.4.3 to address this vulnerability. Name servers running BIND 4 are not affected. To obtain the latest versions of BIND, please visit


Apply a patch or updated version from your vendor

Many operating system vendors include BIND with their products and will be preparing new versions to address this vulnerability. For a list of vendors that the CERT/CC has received information from regarding this vulnerability, please see the Systems Affected section of this document.

Systems Affected

VendorStatusDate NotifiedDate Updated
adnsNot Vulnerable20-Nov-2003
Apple Computer Inc.Vulnerable11-Dec-2003
BlueCat NetworksUnknown21-Oct-2003
BSDIUnknown21-Oct-2003
Check PointNot Vulnerable27-Oct-2003
ConectivaUnknown21-Oct-2003
Cray Inc.Not Vulnerable17-Nov-2003
DebianUnknown21-Oct-2003
EMC CorporationUnknown17-Nov-2003
FreeBSDVulnerable1-Dec-2003
FujitsuUnknown17-Nov-2003
Guardian Digital Inc. Vulnerable2-Dec-2003
Hewlett-Packard CompanyVulnerable3-Dec-2003
HitachiNot Vulnerable25-Nov-2003
IBMVulnerable3-Dec-2003
IBM eServerUnknown17-Nov-2003
ImmunixVulnerable1-Dec-2003
Ingrian NetworksUnknown17-Nov-2003
Internet Software ConsortiumVulnerable1-Dec-2003
Juniper NetworksNot Vulnerable3-Dec-2003
Lucent TechnologiesUnknown17-Nov-2003
MandrakeSoftNot Vulnerable17-Nov-2003
Men&MiceUnknown17-Nov-2003
MetaSolv Software Inc.Unknown21-Oct-2003
MontaVista SoftwareUnknown21-Oct-2003
NEC CorporationUnknown21-Oct-2003
NetBSDVulnerable17-Nov-2003
NixuVulnerable20-Nov-2003
NokiaUnknown21-Oct-2003
NominumNot Vulnerable17-Nov-2003
Nortel NetworksUnknown17-Nov-2003
NovellUnknown17-Nov-2003
Openwall GNU/*/LinuxUnknown21-Oct-2003
Red Hat Inc.Not Vulnerable17-Nov-2003
SequentUnknown21-Oct-2003
SGINot Vulnerable17-Nov-2003
Sony CorporationUnknown17-Nov-2003
Sun Microsystems Inc.Vulnerable1-Dec-2003
SuSE Inc.Vulnerable1-Dec-2003
The SCO Group (SCO Linux)Unknown21-Oct-2003
The SCO Group (SCO UnixWare)Vulnerable3-Dec-2003
Trustix Secure LinuxVulnerable1-Dec-2003
UnisysUnknown21-Oct-2003
Wind River Systems Inc.Unknown17-Nov-2003
WirexUnknown17-Nov-2003

References


http://www.isc.org/products/BIND/bind8.html
http://marc.theaimsgroup.com/?l=bind-announce&m=106988846219834&w=2
http://marc.theaimsgroup.com/?l=bind-announce&m=106988846919846&w=2
http://secunia.com/advisories/10300/

Credit

The CERT/CC thanks the Internet Software Consortium for bringing this vulnerability to our attention.

This document was written by Jeffrey P. Lanza.

Other Information

Date Public:2003-11-26
Date First Published:2003-12-01
Date Last Updated:2004-01-04
CERT Advisory: 
CVE-ID(s):CAN-2003-0914
NVD-ID(s):CAN-2003-0914
US-CERT Technical Alerts: 
Metric:1.50
Document Revision:40

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader