|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU AD-2009-11

Vulnerability in bind (9) causes denial of service via dynamic update request

Original issue date: 29 July, 2009

Overview

A vulnerability has been reported in Bind (9) which is used for Domain Name System (DNS) implementation. Bind supports dynamic DNS updates. BIND 9 can crash when processing a specially-crafted dynamic update packet. This vulnerability affects all Bind based DNS servers even without dynamic update feature.

Description

An attacker can send specially crafted update message DNS requests to a nameserver. These crafted message leads to Denial of Service condition.

When named (8) receives a specially crafted dynamic update message an internal assertion check is triggered which causes named (8) to exit.

To trigger the problem, the dynamic update message must contain a record of type "ANY" and at least one resource record set (RRset) for this fully qualified domain name (FQDN) on the server.

Affected Systems

  • All Bind based DNS servers

Impact

Severity Rating: High

Solution

  • This vulnerability is addressed in ISC BIND versions 9.4.3-P3, 9.5.1-P3, and BIND 9.6.1-P1.
  • Apply appropriate patches or fixes released by respective vendors at server and client level.

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

Vendor Information

Internet Systems Consortium
https://www.isc.org/node/474

FreeBSD
http://security.freebsd.org/advisories/FreeBSD-SA-09:12.bind.asc

CVE Name

CVE-2009-0696

References


Internet Systems Consortium


https://www.isc.org/node/474


 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +

09-Jul-2011