Vulnerability Note VU#938617
BIND 9.3.0 vulnerable to denial of service in validator code
Overview
A vulnerability in the BIND name server could allow a remote attacker to cause a denial of service against an affected system.
Description
The Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS) implementation from Internet Systems Consortium (ISC). BIND supports the DNS Security Extensions (DNSSEC), including the NextSECure (NSEC) RDATA Format defined by RFC3845. An incorrect assumption in the validator function authvalidated()can result in an internal consistancy test failing and named exiting. An attacker with the ability to craft specific DNS packets could exploit this vulnerability to cause a denial of service. This vulnerability only affects BIND version 9.3.0. |
Impact
A remote attacker may be able to cause the name server daemon to exit prematurely, thereby causing a denial of service for DNS operations. |
Solution
Apply a patch from the vendor Patches have been released in response to this issue. Please see the Systems Affected section of this document. |
Workarounds
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| FreeBSD | Affected | 17 Jan 2005 | 21 Jun 2005 |
| ISC | Affected | - | 25 Jan 2005 |
| MandrakeSoft | Affected | 17 Jan 2005 | 31 Jan 2005 |
| Trustix Secure Linux | Affected | - | 16 Feb 2005 |
| Apple Computer Inc. | Not Affected | 17 Jan 2005 | 18 Mar 2005 |
| Check Point | Not Affected | 17 Jan 2005 | 24 Jan 2005 |
| Debian | Not Affected | 17 Jan 2005 | 25 Jan 2005 |
| Hitachi | Not Affected | 17 Jan 2005 | 20 Jan 2005 |
| IBM | Not Affected | 17 Jan 2005 | 24 Jan 2005 |
| InfoBlox | Not Affected | 04 Feb 2005 | 18 Mar 2005 |
| Juniper Networks | Not Affected | 17 Jan 2005 | 24 Jan 2005 |
| NEC Corporation | Not Affected | 17 Jan 2005 | 18 Mar 2005 |
| Red Hat Inc. | Not Affected | 17 Jan 2005 | 18 Jan 2005 |
| Sun Microsystems Inc. | Not Affected | 17 Jan 2005 | 24 Jan 2005 |
| Adns | Unknown | 17 Jan 2005 | 17 Jan 2005 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.isc.org/sw/bind/bind-security.php
- http://www.niscc.gov.uk/niscc/docs/al-20050125-00060.html?lang=en
Credit
Thanks to Joao Damas of the Internet Systems Consortium for reporting this vulnerability.
This document was written by Chad Dougherty based on information provided by ISC.
Other Information
- CVE IDs: CAN-2005-0034
- Date Public: 25 Jan 2005
- Date First Published: 25 Jan 2005
- Date Last Updated: 21 Jun 2005
- Severity Metric: 1.91
- Document Revision: 20
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.