SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#955777

Multiple vulnerabilities in DNS implementations

Overview

Numerous vulnerabilities have been reported in various Domain Name System (DNS) implementations. The impacts of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, or cause a DNS implementation to behave in an unstable/unpredictable manner.

I. Description

DNS

The Domain Name System provides name, address, and other information about Internet Protocol (IP) networks and devices.

The Problems

The U.K. National Infrastructure Security Co-ordination Center (NISCC) and the Oulu University Secure Programming Group have reported numerous vulnerabilities in DNS implementations.

These vulnerabilities were discovered using the PROTOS DNS Test Tool developed by Oulu University Secure Programming Group (OUSPG). The results of the tests are described in NISCC Vulnerability Advisory 144154/NISCC/DNS. According to that advisory:

    There are three sets of test materials available with the tool; these are specifically designed for the following scenarios:

    1. The Query Material -> [queries, dynamic DNS updates] -> DNS server
    2. The Response Material -> [query replies] -> DNS server
    3. The Response Material -> [query replies] -> DNS stub resolver (client)
    4. The Zone Transfer Material -> [zone transfers] -> secondary DNS server


    The test material simulates hostile input to the DNS implementation by sending invalid
    and/or abnormal packets.

II. Impact

These vulnerabilities may allow a remote attacker to execute arbitrary code, cause a denial-of-service condition, gain access to sensitive information, or cause an DNS implementation to behave in an unstable/unpredictable manner.


Exploitation of some of these vulnerabilities may allow a remote attacker to take control of a DNS server. Once a DNS server compromised, the attacker may be able to launch attacks on other, unaffected DNS servers.

III. Solution

Apply a patch from an affected product vendor

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Unknown26-Apr-2006
Conectiva Inc.Unknown26-Apr-2006
Cray Inc.Unknown26-Apr-2006
Debian GNU/LinuxUnknown26-Apr-2006
EMC, Inc. (formerly Data General Corporation)Unknown26-Apr-2006
Engarde Secure LinuxUnknown26-Apr-2006
F5 Networks, Inc.Vulnerable3-May-2006
Fedora ProjectUnknown26-Apr-2006
FreeBSD, Inc.Unknown26-Apr-2006
FujitsuUnknown26-Apr-2006
Gentoo LinuxUnknown26-Apr-2006
Hewlett-Packard CompanyNot Vulnerable10-May-2006
HitachiNot Vulnerable1-May-2006
IBM CorporationUnknown26-Apr-2006
IBM Corporation (zseries)Unknown26-Apr-2006
IBM eServerUnknown27-Apr-2006
Immunix Communications, Inc.Unknown26-Apr-2006
Ingrian Networks, Inc.Unknown26-Apr-2006
Internet Software ConsortiumUnknown26-Apr-2006
Juniper Networks, Inc.Vulnerable27-Apr-2006
Mandriva, Inc.Unknown26-Apr-2006
Microsoft CorporationUnknown26-Apr-2006
MontaVista Software, Inc.Unknown26-Apr-2006
NEC CorporationUnknown26-Apr-2006
NetBSDUnknown26-Apr-2006
NokiaUnknown26-Apr-2006
Novell, Inc.Unknown26-Apr-2006
OpenBSDUnknown26-Apr-2006
Openwall GNU/*/LinuxVulnerable10-May-2006
QNX, Software Systems, Inc.Unknown26-Apr-2006
Red Hat, Inc.Unknown26-Apr-2006
Ricoh CorporationNot Vulnerable23-May-2006
Silicon Graphics, Inc.Unknown26-Apr-2006
Slackware Linux Inc.Unknown26-Apr-2006
Sony CorporationUnknown26-Apr-2006
Sun Microsystems, Inc.Unknown22-May-2006
SUSE LinuxUnknown26-Apr-2006
Trustix Secure LinuxUnknown26-Apr-2006
TurbolinuxUnknown26-Apr-2006
UbuntuUnknown26-Apr-2006
UnisysUnknown26-Apr-2006
Wind River Systems, Inc.Unknown26-Apr-2006

References


http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/dns/index.html
http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html
http://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=en
http://jvn.jp/niscc/NISCC-144154/index.html

Credit

These vulnerabilities were reported by NISCC and Oulu University Secure Programming Group (OUSPG)

This document was written by Jeff Gennari.

Other Information

Date Public:2006-04-25
Date First Published:2006-04-28
Date Last Updated:2006-05-23
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:19.12
Document Revision:37

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader