J-Security Center

Title: Multiple Vendor DNS Cache Corruption Vulnerability

Severity: HIGH

Description:

BIND (Berkeley Internet Name Daemon) is the software packge most widely deployed on the Internet to facilitate DNS (Domain Name Service). BIND has a series of utilities that come with it in order to deploy DNS both client (resolver libraries etc.) and server end (named). In this instance we are discussing a bug in the Name Server or named(8) which ships with BIND 4.9.5-P1 or below.

This particular vulnerability is that a name daemon from these distributions will blindly recieve records from other DNS servers and cache them without verifification. Therefore, intruders who control a nameserver on the global internet can force your nameserver to look up data from them and then feed it back additional and corrupt records. These records are typically designed to live in your cache and divert traffic from legitimate sites.

In the referance section to this vulnerability is a message from Johannes Erdfelt (johan@BORG.SVENTECH.COM) detailing this problem, it is suggested reading. it also important to note that while this is the most recent cache corruption attack it is not the only such one. BIND has a long history of security vulnerabilties.

Affected Products:

  • BSDI BSD/OS 2.0.1
  • Data General DG/UX 5.4 4.11.0
  • HP HP-UX (VVOS) 10.24.0
  • HP HP-UX 10.20.0
  • NEC UX/4800 (64)
  • SCO Open Server 5.0.0
  • SGI IRIX 4.0.2
  • SGI IRIX 4.0.3
  • SGI IRIX 4.0.4
  • SGI IRIX 4.0.4 B
  • SGI IRIX 4.0.4 T
  • SGI IRIX 4.0.5
  • SGI IRIX 4.0.5 (IOP)
  • SGI IRIX 4.0.5 A
  • SGI IRIX 4.0.5 D
  • SGI IRIX 4.0.5 E
  • SGI IRIX 4.0.5 F
  • SGI IRIX 4.0.5 G
  • SGI IRIX 4.0.5 H
  • SGI IRIX 4.0.5 IPR
  • SGI IRIX 5.0.0
  • SGI IRIX 5.0.1
  • SGI IRIX 5.1.0
  • SGI IRIX 5.2.0
  • SGI IRIX 5.3.0
  • SGI IRIX 5.3.0 XFS
  • SGI IRIX 6.0.0
  • SGI IRIX 6.0.1
  • SGI IRIX 6.1.0
  • SGI IRIX 6.2.0
  • SGI IRIX 6.3.0
  • SGI IRIX 6.4.0
  • Sun Solaris 2.3.0
  • Sun Solaris 2.4.0
  • Sun Solaris 2.4.0_x86
  • Sun Solaris 2.5.0
  • Sun Solaris 2.5.0_x86
  • Sun Solaris 2.5.1
  • Sun Solaris 2.5.1_ppc
  • Sun Solaris 2.5.1_x86
  • Sun Solaris 2.6
  • Sun Solaris 2.6_x86
  • Sun SunOS 4.1.3
  • Sun SunOS 4.1.3 _U1
  • Sun SunOS 4.1.4

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.