SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#739123

ISC BIND 9 fails to process additional data chains in responses correctly thereby causing the server to fail an internal consistency check

Overview

A denial-of-service vulnerability exists in version 9 of the Internet Software Consortium's (ISC) Berkeley Internet Name Domain (BIND) server. ISC BIND versions 8 and 4 are not affected. Exploiting this vulnerability will cause vulnerable BIND servers to shut down.

I. Description

BIND is an implementation of the Domain Name System (DNS) that is maintained by the ISC. A vulnerability in Version 9 of BIND exists which may result in the deliberate shutdown of vulnerable BIND servers by arbitrary remote attackers. The shutdown can be caused by a specific DNS packet designed to create an improperly-handled error condition. Because the error condition is correctly detected but is not handled properly, this vulnerability will not allow an intruder to execute arbitrary code or write data to arbitrary locations in memory. The error condition that triggers the shutdown occurs when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL as expected. The condition causes the code to assert an error message and call abort() to shutdown the BIND server.

II. Impact

Exploitation of this vulnerability will cause the vulnerable BIND server to abort and shut down. As a result, the BIND server will not be available unless restarted.

III. Solution

Apply a patch from your vendor or upgrade to BIND 9.2.1. BIND 9.2.1 is available from http://www.isc.org/products/BIND/bind9.html.

Systems Affected

VendorStatusDate Updated
3ComUnknown30-May-2002
AlcatelNot Vulnerable18-Sep-2002
Apple Computer Inc.Not Vulnerable31-May-2002
AT&TUnknown30-May-2002
BSDINot Vulnerable4-Jun-2002
Cisco Systems Inc.Unknown30-May-2002
Compaq Computer CorporationNot Vulnerable4-Jun-2002
Cray Inc.Not Vulnerable30-May-2002
Data GeneralUnknown30-May-2002
DebianUnknown30-May-2002
djbdnsNot Vulnerable11-Jun-2002
EngardeNot Vulnerable30-May-2002
F5 NetworksVulnerable11-Jun-2002
FreeBSDNot Vulnerable30-May-2002
FujitsuUnknown30-May-2002
Hewlett-Packard CompanyVulnerable8-Aug-2002
IBMNot Vulnerable4-Jun-2002
IBM-zSeriesUnknown30-May-2002
Inktomi CorporationNot Vulnerable11-Jun-2002
IntelUnknown30-May-2002
ISCVulnerable30-May-2002
Juniper NetworksUnknown30-May-2002
LucentUnknown30-May-2002
MandrakeSoftVulnerable3-Jun-2002
Microsoft CorporationNot Vulnerable30-May-2002
NEC CorporationNot Vulnerable3-Jun-2002
NetBSDVulnerable4-Jun-2002
Network ApplianceNot Vulnerable3-Jun-2002
Nortel NetworksUnknown4-Jun-2002
OpenBSDUnknown30-May-2002
Red Hat Inc.Vulnerable3-Jun-2002
SequentUnknown30-May-2002
SGINot Vulnerable30-May-2002
Sony CorporationUnknown30-May-2002
Sun Microsystems Inc.Not Vulnerable31-May-2002
SuSE Inc.Vulnerable3-Jun-2002
The SCO Group (SCO UnixWare)Vulnerable13-Sep-2002
Unisphere NetworksNot Vulnerable30-May-2002
UnisysUnknown30-May-2002
Wind River Systems Inc.Unknown30-May-2002

References


http://www.isc.org/products/BIND/bind9.html
ftp://ftp.isc.org/isc/bind9/9.2.1/bind-9.2.1.tar.gz
ftp://ftp.isc.org/isc/bind9/9.2.1/bind-9.2.1.tar.gz.asc
ftp://ftp.isc.org/isc/bind/contrib/ntbind-9.2.1/BIND9.2.1.zip
ftp://ftp.isc.org/isc/bind/contrib/ntbind-9.2.1/BIND9.2.1.zip.asc
http://www.securityfocus.com/bid/4936

Credit

The CERT/CC thanks the Internet Software Consortium (ISC) for reporting this vulnerability to us.

This document was written by Ian A. Finlay.

Other Information

Date Public05/04/2001
Date First Published06/04/2002 04:19:52 PM
Date Last Updated09/18/2002
CERT AdvisoryCA-2002-15
CVE NameCAN-2002-0400
US-CERT Technical Alerts 
Metric40.80
Document Revision56

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader