Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 5th, 2011, 18:20 GMT · By

Remote Denial of Service Vulnerability Patched in BIND

SHARE:

Adjust text size:


BIND update fixes dangerous remote DoS vulnerability
Enlarge picture
The Internet Systems Consortium (ISC) has released security updates for the BIND DNS daemon in order to address two serious vulnerabilities that can crash servers.

"A defect in the affected BIND 9 versions allows an attacker to remotely cause the "named" process to exit using a specially crafted packet. This defect affects both recursive and authoritative servers," the organization warns in one advisory.

The nature of the bug makes it impossible to protect servers via access lists or by disabling features when compiling or running the daemon.

If the server is not facing the Internet, an attacker can still target it via malware installed on computers inside the network where it is located.

The vulnerability carries a CVSS score of 7.8 out of 10. The solution is to upgrade immediately to BIND 9.6-ESV-R4-P3, 9.7.3-P3 or 9.8.0-P4.

"ISC thanks Roy Arends from Nominet for pin-pointing the exact nature of the vulnerability. We also thank Ramesh Damodaran of Infoblox for finding a variation of the attack vector and Mats Dufberg of TeliaSonera Sweden for confirming additional variants," the organization said.

The second issue patched in the popular DNS daemon concerns two defects that affect BIND 9 servers with recursion enabled and which use Response Policy Zones (RPZ).

This issue can lead to a server crash, but because the RPZ needs to contain specific rules/action patterns for this to happen, the risks are more limited.

The vulnerability carries a CVSS score of 7.8, but it cannot be exploited remotely. The solution is to upgrade to BIND 9.8.0-P4 as soon as possible or not put certain CNAME or any DNAME records into an RPZ zone.

BIND is the most widely used DNS server software and is distributed by default with the majority of Unix and Linux platforms. It is being maintained by the Internet Systems Consortium (ISC), a non-profit corporation that develops and maintains several software projects critical to the Internet infrastructure.

TELL US WHAT YOU THINK:

1,263 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Dangerous Denial of Service Bug Patched in BIND

Serious Vulnerability Patched in Popular DHCP Software

High Risk Denial of Service Vulnerability Identified in BIND

BIND DNS Servers Vulnerable to Denial of Service Attacks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM