SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#927905

BIND version 8 generates cryptographically weak DNS query identifiers

Overview

ISC BIND version 8 generates cryptographically weak DNS query IDs which could allow a remote attacker to poison DNS caches.

I. Description

The Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS) implementation from Internet Systems Consortium (ISC). Version 8 of the BIND software uses a weak algorithm to generate DNS query identifiers. This condition allows an attacker to reliably guess the next query ID, thereby allowing for DNS cache poisoning attacks.

ISC states that this bug only affects outgoing queries, generated by BIND 8 to answer questions as a resolver, or when it is looking up data for internal uses, such as when sending NOTIFY messages to slave name servers. Note that although this vulnerability is similar in nature and impact to VU#252735, it is a distinct issue.

II. Impact

A remote attacker with the ability to predict DNS query IDs and respond with arbitrary answers, could poison DNS caches.

III. Solution

Upgrade or apply a patch


Users should obtain a patch from their operating system vendor when available. Please see the Systems Affected section of this document for more information about specific vendors.

Users who compile their own versions of BIND 8 from the original ISC source code are encouraged to take the following actions described by ISC:

    This issue is addressed in ISC BIND 8.4.7-P1, available as patch that  
    can be applied to BIND 8.4.7.
    The more definitive solution is to upgrade to BIND 9. BIND 8 is being  
    declared "end of life" by ISC due to multiple architectural issues.  
    See ISC's website at http://www.isc.org for more information and  
    assistance.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Unknown27-Aug-2007
BlueCat Networks, Inc.Not Vulnerable28-Aug-2007
Check Point Software TechnologiesUnknown27-Aug-2007
Conectiva Inc.Unknown27-Aug-2007
Cray Inc.Unknown27-Aug-2007
Debian GNU/LinuxUnknown27-Aug-2007
EMC CorporationUnknown27-Aug-2007
Engarde Secure LinuxUnknown27-Aug-2007
F5 Networks, Inc.Unknown27-Aug-2007
Fedora ProjectUnknown27-Aug-2007
FreeBSD, Inc.Unknown27-Aug-2007
FujitsuUnknown27-Aug-2007
Gentoo LinuxUnknown27-Aug-2007
Gnu ADNSUnknown27-Aug-2007
GNU glibcUnknown27-Aug-2007
Hewlett-Packard CompanyUnknown27-Aug-2007
HitachiUnknown27-Aug-2007
IBM CorporationUnknown27-Aug-2007
IBM Corporation (zseries)Unknown27-Aug-2007
IBM eServerUnknown27-Aug-2007
Immunix Communications, Inc.Unknown27-Aug-2007
InfobloxNot Vulnerable27-Aug-2007
Ingrian Networks, Inc.Unknown27-Aug-2007
Internet Software ConsortiumVulnerable27-Aug-2007
Juniper Networks, Inc.Unknown27-Aug-2007
Lucent TechnologiesUnknown27-Aug-2007
Mandriva, Inc.Not Vulnerable27-Aug-2007
Men & MiceUnknown27-Aug-2007
Metasolv Software, Inc.Unknown27-Aug-2007
Microsoft CorporationNot Vulnerable28-Aug-2007
MontaVista Software, Inc.Unknown27-Aug-2007
NEC CorporationUnknown27-Aug-2007
NetBSDUnknown27-Aug-2007
Nortel Networks, Inc.Unknown27-Aug-2007
Novell, Inc.Unknown27-Aug-2007
OpenBSDUnknown27-Aug-2007
Openwall GNU/*/LinuxUnknown27-Aug-2007
QNX, Software Systems, Inc.Unknown27-Aug-2007
Red Hat, Inc.Unknown27-Aug-2007
ShadowsupportUnknown27-Aug-2007
Silicon Graphics, Inc.Unknown27-Aug-2007
Slackware Linux Inc.Unknown27-Aug-2007
Sony CorporationUnknown27-Aug-2007
Sun Microsystems, Inc.Unknown27-Aug-2007
SUSE LinuxUnknown27-Aug-2007
The SCO GroupUnknown27-Aug-2007
Trustix Secure LinuxUnknown27-Aug-2007
TurbolinuxUnknown27-Aug-2007
UbuntuUnknown27-Aug-2007
UnisysUnknown27-Aug-2007
Wind River Systems, Inc.Unknown27-Aug-2007

References


http://www.isc.org/index.pl?/sw/bind/bind8-eol.php
http://www.trusteer.com/docs/bind8dns.html
http://secunia.com/advisories/26629/

Credit

Thanks to the Internet Systems Consortium (ISC) for reporting this vulnerability. ISC, in turn, credits Amit Klein from Trusteer for reporting this issue to them.

This document was written by Chad Dougherty.

Other Information

Date Public:2007-08-27
Date First Published:2007-08-28
Date Last Updated:2007-08-28
CERT Advisory: 
CVE-ID(s):CVE-2007-2930
NVD-ID(s):CVE-2007-2930
US-CERT Technical Alerts: 
Metric:2.14
Document Revision:14

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader