Sun Solaris in.named(1M) dynamic update denial of service
| solaris-innamed-dynamic-dos (17269) |
Description:
Sun Solaris is vulnerable to a denial of service attack when handling dynamic updates. If the system is configured as an Internet DNS server, a privileged remote attacker could cause the in.named(1M) daemon to crash.
Consequences:
Denial of Service
Remedy:
Apply the appropriate patch for your system, as listed below. Refer to Sun Alert ID: 57614 for more information. See References.
SPARC Platform
Solaris 8: 109326-16 or later
x86 Platform
Solaris 8: 109327-16 or later
References:
- Sun Alert ID: 57614: The in.named(1M) Process May Die Upon Receiving Dynamic Updates .
- BID-11118: Sun Solaris in.named Remote Denial of Service Vulnerability
- CVE-2004-1348: Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).
- SA12470: Sun Solaris in.named Dynamic Update Denial of Service Vulnerability
Platforms Affected:
- Sun Solaris 8
Reported:
Sep 03, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
