search menu icon-carat-right cmu-wordmark

CERT Coordination Center

ISC BIND 9 named denial of service vulnerability

Vulnerability Note VU#142646

Original Release Date: 2011-07-05 | Last Revised: 2011-07-20

Overview

ISC BIND 9 contains a remote packet denial of service vulnerability when running as an authoritative or recursive server.

Description

According to ISC:

A defect in the affected BIND 9 versions allows an attacker to remotely cause the "named" process to exit using a specially crafted packet. This defect affects both recursive and authoritative servers. The code location of the defect makes it impossible to protect BIND using ACLs configured within named.conf or by disabling any features at compile-time or run-time.

A remote attacker would need to be able to send a specially crafted packet directly to a server running a vulnerable version of BIND. There is also the potential for an indirect attack via malware that is inadvertently installed and run, where infected machines have direct access to an organization's nameservers.

Impact

A remote, unauthenticated attacker can cause the named daemon to crash creating a denial of service condition.

Solution

Apply an update

Users who obtain BIND from a third-party vendor, such as their operating system vendor, should see the vendor information portion of this document for a partial list of affected vendors.

This vulnerability is addressed in ISC BIND versions 9.6-ESV-R4-P3, 9.7.3-P3 and 9.8.0-P4. Users of BIND from the original source distribution should upgrade to this version.

See also http://www.isc.org/software/bind/advisories/cve-2011-2464

Vendor Information

142646
 

Debian GNU/Linux Affected

Updated:  July 07, 2011

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

For the oldstable distribution (lenny), this problem has been fixed in

version 1:9.6.ESV.R4+dfsg-0+lenny3.

For the stable distribution (squeeze), this problem has been fixed in
version 1:9.7.3.dfsg-1~squeeze3.

The testing distribution (wheezy) and the unstable distribution (sid)
will be fixed later.

We recommend that you upgrade your bind9 packages.

Internet Systems Consortium Affected

Notified:  June 16, 2011 Updated: July 05, 2011

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Mandriva S. A. Affected

Updated:  July 20, 2011

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

Mandriva Linux 2009.0:

ca6c480f7a3738227e5a7190ec1499b7 2009.0/i586/bind-9.7.3-0.0.P3.1.1mdv2009.0.i586.rpm
09875b79c8645d5435ce653a7d2844b9 2009.0/i586/bind-devel-9.7.3-0.0.P3.1.1mdv2009.0.i586.rpm
abb841d7abc6ac1a69cf28af7c2e5e19 2009.0/i586/bind-doc-9.7.3-0.0.P3.1.1mdv2009.0.i586.rpm
db42fa2094b45da2ead8c614ea8f39b0 2009.0/i586/bind-utils-9.7.3-0.0.P3.1.1mdv2009.0.i586.rpm
2e3ba946b0a13c0a424a1597f255dcb5 2009.0/SRPMS/bind-9.7.3-0.0.P3.1.1mdv2009.0.src.rpm

Mandriva Linux 2009.0/X86_64:
f58b8e207e209cef128693b7049d162f 2009.0/x86_64/bind-9.7.3-0.0.P3.1.1mdv2009.0.x86_64.rpm
dc1085555707774e4e9709891aa79dd1 2009.0/x86_64/bind-devel-9.7.3-0.0.P3.1.1mdv2009.0.x86_64.rpm
1e34f338c7ba785e0271859b22ab2c28 2009.0/x86_64/bind-doc-9.7.3-0.0.P3.1.1mdv2009.0.x86_64.rpm
00dc003c8fe9c03c7122300d81d91905 2009.0/x86_64/bind-utils-9.7.3-0.0.P3.1.1mdv2009.0.x86_64.rpm
2e3ba946b0a13c0a424a1597f255dcb5 2009.0/SRPMS/bind-9.7.3-0.0.P3.1.1mdv2009.0.src.rpm

Mandriva Linux 2010.1:
aeb3ed5e5f630ff5aac1429fe59907df 2010.1/i586/bind-9.7.3-0.0.P3.1.1mdv2010.2.i586.rpm
10b785d8384c7f8f7b600cc36023446a 2010.1/i586/bind-devel-9.7.3-0.0.P3.1.1mdv2010.2.i586.rpm
6afb5e313edd48b9c960ecebd73af92e 2010.1/i586/bind-doc-9.7.3-0.0.P3.1.1mdv2010.2.i586.rpm
f135331906181bb6da064259ecbc647a 2010.1/i586/bind-utils-9.7.3-0.0.P3.1.1mdv2010.2.i586.rpm
f130951f40fdbde979c9999f2bc29ccf 2010.1/SRPMS/bind-9.7.3-0.0.P3.1.1mdv2010.2.src.rpm

Mandriva Linux 2010.1/X86_64:
7eeb4c6916e8dc5ecc2b7284c733ea8e 2010.1/x86_64/bind-9.7.3-0.0.P3.1.1mdv2010.2.x86_64.rpm
f7687346e5c7072395a0d158f7070d9f 2010.1/x86_64/bind-devel-9.7.3-0.0.P3.1.1mdv2010.2.x86_64.rpm
1e890bc2ba91af8d3fa57c7a7bd008c7 2010.1/x86_64/bind-doc-9.7.3-0.0.P3.1.1mdv2010.2.x86_64.rpm
bdf6a36d8c002d6ad62eeb83b6dc54fc 2010.1/x86_64/bind-utils-9.7.3-0.0.P3.1.1mdv2010.2.x86_64.rpm
f130951f40fdbde979c9999f2bc29ccf 2010.1/SRPMS/bind-9.7.3-0.0.P3.1.1mdv2010.2.src.rpm

Mandriva Enterprise Server 5:
750c707ab5d471f54a2e62a265628b05 mes5/i586/bind-9.7.3-0.0.P3.1.1mdvmes5.2.i586.rpm
a4cc134f17c999467986e03e5a5caa18 mes5/i586/bind-devel-9.7.3-0.0.P3.1.1mdvmes5.2.i586.rpm
eb4cb65573546064202eda0a494de398 mes5/i586/bind-doc-9.7.3-0.0.P3.1.1mdvmes5.2.i586.rpm
f5cad026fb2402b78be8d1eb340a9ef9 mes5/i586/bind-utils-9.7.3-0.0.P3.1.1mdvmes5.2.i586.rpm
092f9de8063f70ced41bfdfb6c4edbad mes5/SRPMS/bind-9.7.3-0.0.P3.1.1mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
3b5a09e53f39c5135dd72638be00ba59 mes5/x86_64/bind-9.7.3-0.0.P3.1.1mdvmes5.2.x86_64.rpm
61251e33bc1e649e7b5da91dcfd4c6b1 mes5/x86_64/bind-devel-9.7.3-0.0.P3.1.1mdvmes5.2.x86_64.rpm
2b8bfeca87fb28326b4c2e76ae7dc920 mes5/x86_64/bind-doc-9.7.3-0.0.P3.1.1mdvmes5.2.x86_64.rpm
ceb92e09171cf5ef0eee8a04e4a52fec mes5/x86_64/bind-utils-9.7.3-0.0.P3.1.1mdvmes5.2.x86_64.rpm
092f9de8063f70ced41bfdfb6c4edbad mes5/SRPMS/bind-9.7.3-0.0.P3.1.1mdvmes5.2.src.rpm

Red Hat, Inc. Affected

Updated:  July 07, 2011

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Internet Systems Consortium for reporting this vulnerability.

This document was written by Michael Orlando.

Other Information

CVE IDs: CVE-2011-2464
Severity Metric: 17.85
Date Public: 2011-07-05
Date First Published: 2011-07-05
Date Last Updated: 2011-07-20 18:57 UTC
Document Revision: 15

Sponsored by CISA.