ISC BIND DNS query spoofing
| iscbind-dns-query-spoofing (36275) |
Description:
ISC BIND could allow a remote attacker to poison the DNS cache, caused by a vulnerability in the DNS query ID generation code where predictable query IDs in only outgoing queries are generated. By observing some consecutive transaction ID values, a remote attacker could exploit this vulnerability to guess the next query ID and perform DNS Cache Poisoning.
*CVSS:
| Base Score: | 4.3 |
| Access Vector: | Network |
| Access Complexity: | Medium |
| Authentication: | None |
| Confidentiality Impact: | None |
| Integrity Impact: | Partial |
| Availability Impact: | None |
| Temporal Score: | 3.6 |
| Exploitability: | Functional |
| Remediation Level: | Official-Fix |
| Report Confidence: | Confirmed |
Consequences:
Gain Access
Remedy:
Upgrade to the latest version of BIND (8.4.7-P1 or 9.4.1-P1 or later), available from the Internet Software Consortium (ISC) Web site. See References.
For Solaris (BIND):
Refer to Sun Alert ID: 103063 for patch, upgrade or suggested workaround information. See References.
For AIX 5.2.0:
Apply APAR IZ05609, available from the IBM Quick Links Web site. See References.
For AIX 5.3.0:
Apply APAR IZ05686, available from the IBM Quick Links Web site. See References.
--OR--
Apply the interim fix for this vulnerability (bind8_ifix.tar), available from the IBM AIX FTP site. See References.
For other distributions:
Apply the appropriate update for your system. See References.
References:
- BugTraq Mailing List, Mon Aug 27 2007 - 14:01:56 CDT: BIND 8 EOL and BIND 8 DNS Cache Poisoning (Amit Klein, Trusteer).
- HPSBUX02289 SSRT071461 : HP-UX Running BIND 8, Remote DNS Cache Poisoning.
- IBM SECURITY ADVISORY: AIX BIND 8 remote DNS cache poisoning.
- Internet Software Consortium (ISC) Web site: BIND (Berkeley Internet Name Domain) page.
- Nortel Response to Potential Vunerability VU#927905: BIND 8 May Allow Cache Poisoning Attack.
- Nortel Security Bulletin ID: 2008008807, Rev 1: Nortel response to Sun Alert 200859 - Security Vulnerability in BIND 8 May Allow Cache Poisoning Attack.
- Sun Alert ID: 103063: Security Vulnerability in BIND 8 May Allow Cache Poisoning Attack.
- ASA-2007-448: Security Vulnerability in BIND 8 May Allow Cache Poisoning Attack (Sun 103063)
- ASA-2008-022: HP-UX Running BIND 8 Remote DNS Cache Poisoning (HPSBUX02289)
- BID-25459: ISC BIND 8 Remote Cache Poisoning Vulnerability
- CVE-2007-2930: The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926.
- SA26629: BIND 8 Predictable DNS Query IDs Vulnerability
- SA26858: Sun Solaris BIND 8 Predictable DNS Query IDs Vulnerability
- SA27433: Nortel Business Communications Manager BIND 8 Predictable DNS Query IDs
- SA27459: Avaya CMS / IR BIND Predictable DNS Query IDs Vulnerability
- SA27465: IBM AIX BIND 8 Predictable DNS Query IDs Vulnerability
- SECTRACK ID: 1018615: BIND 8 Transaction ID Generation Algorithm Lets Remote Users Conduct DNS Cache Poisoning Attacks
- US-CERT VU#927905: BIND version 8 generates cryptographically weak DNS query identifiers
- VUPEN/ADV-2007-2991: ISC BIND 8 DNS Query ID Generation Weakness Cache Poisoning Vulnerability
- VUPEN/ADV-2007-3192: Sun Solaris Security Update Fixes Bind ID Generation DNS Cache Poisoning
- VUPEN/ADV-2007-3639: Nortel Business Communications Manager Bind DNS Cache Poisoning
- VUPEN/ADV-2007-3668: IBM AIX Bind Query ID Generation DNS Cache Poisoning Vulnerability
- VUPEN/ADV-2007-3936: HP-UX Bind Query ID Generation DNS Cache Poisoning Vulnerability
Platforms Affected:
- Avaya Call Management System
- Avaya Interactive Response
- HP HP-UX B.11.11
- IBM AIX 5.2
- IBM AIX 5.3
- ISC BIND 4
- ISC BIND 4.9
- ISC BIND 4.9.10
- ISC BIND 4.9.2
- ISC BIND 4.9.3
- ISC BIND 4.9.4
- ISC BIND 4.9.5
- ISC BIND 4.9.5 P1
- ISC BIND 4.9.6
- ISC BIND 4.9.7
- ISC BIND 4.9.8
- ISC BIND 4.9.9
- ISC BIND 8
- ISC BIND 8.1
- ISC BIND 8.1.1
- ISC BIND 8.1.2
- ISC BIND 8.2
- ISC BIND 8.2 P1
- ISC BIND 8.2.1
- ISC BIND 8.2.2 P1
- ISC BIND 8.2.2 P7
- ISC BIND 8.2.2 P5
- ISC BIND 8.2.2 P3
- ISC BIND 8.2.2
- ISC BIND 8.2.2 P2
- ISC BIND 8.2.2 P4
- ISC BIND 8.2.2 P6
- ISC BIND 8.2.3
- ISC BIND 8.2.3_t1a
- ISC BIND 8.2.3_t9b
- ISC BIND 8.2.4
- ISC BIND 8.2.5
- ISC BIND 8.2.6
- ISC BIND 8.2.7
- ISC BIND 8.3.0
- ISC BIND 8.3.1
- ISC BIND 8.3.2
- ISC BIND 8.3.3
- ISC BIND 8.3.4
- ISC BIND 8.3.5
- ISC BIND 8.3.6
- ISC BIND 8.4
- ISC BIND 8.4.1
- ISC BIND 8.4.4
- ISC BIND 8.4.5
- ISC BIND 8.4.7
Reported:
Aug 27, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
