|
![]() ![]() |
CERT® Advisory CA-1998-05 Multiple Vulnerabilities in BINDOriginal issue date: April 8, 1998Last revised: November 16, 1998 Added vendor information for Data General A complete revision history is at the end of this file.
I. DescriptionThis advisory describes three distinct problems in BIND. Topic 1 describes a vulnerability that may allow a remote intruder to gain root access on your name server or to disrupt normal operation of your name server. Topics 2 and 3 deal with vulnerabilities that can allow an intruder to disrupt your name server. Detailed descriptions of each problem and its solutions are included in the individual sections on each topic.II. ImpactTopic 1: A remote intruder can gain root-level access to your name server.Topics 2 and 3: A remote intruder is able to disrupt normal operation of your name server. III. SolutionAll three problems can be fixed by upgrading to the latest version of BIND, which may be available from your vendor (see Appendix A of this advisory). Questions about the availability of patches from your vendor should be directed to your vendor. Additionally, the Internet Software Consortium has announced new publicly available versions of BIND on the BIND WWW page (http://www.isc.org/bind.html) and on the USENET newsgroup comp.protocols.dns.bind. Additionally, patches are provided for Topics 1 and 3, along with steps to take until you can apply the patch or upgrade to the latest version of BIND.
BIND 8 In addition, unlike BIND 8, inverse query support can be enabled when
the server is compiled. Examine conf/options.h in the source. If the
line #defining INVQ is not commented out, then the server is
vulnerable.
This file is not PGP signed. It has the following MD5 checksum:
This file is not PGP signed. It has the following MD5 checksum:
BIND 8 Most sites will not contain such a record in their configuration
files. However, it is possible for an attacker to engineer such a
record into the cache of a vulnerable nameserver and thus cause a
denial of service.
If the global zone transfer ACL in the options block has been set to
deny access and has no self-referential CNAMEs in its authoritative
zones, then the server is not vulnerable.
Otherwise, the server is vulnerable. The nameserver is recursive by
default, fetches glue by default, and the default global transfer ACL
allows all hosts; so many BIND 8 servers will be vulnerable to this
problem.
(Note: the in.named(8) man page mentions that sending a SIGINT to the
in.named process will dump the current data base and cache to, by
default, /var/tmp/named_dump.db. Some sites may find this useful in
looking for self-referential CNAMEs. Please see the in.named(8) man
page for further details.)
None of the domains for which the server is authoritative should have
self-referential CNAMEs.
This file is not PGP signed. It has the following MD5 checksum:
MD5 (BIND8.1.1_patch.txt) = 33f9dc2eaf221dd48553f490259c2a8b
Notes:
Appendix A - Vendor InformationBelow is a list of the vendors who have provided information for this advisory. We will update this appendix as we receive additional information. If you do not see your vendor's name, the CERT/CC did not hear from that vendor. Please contact the vendor directly.
Berkeley Software Design, Inc. (BSDI)
Caldera CorporationWorkaround for Topic 1:Disable inverse queries by editing named.conf so that either there is no "fake-iquery" entry in the "options" block, or so that the entry is "fake-iquery no;"
Workaround for Topic 2:
For example, if the server was authoritative for "example", adding allow-transfer { any; }; to the "zone" statement for "example" would allow anyone to transfer "example". None of the domains the server is authoritative for should have self-referential CNAMEs.
Correction for both Topics: ftp://ftp.caldera.com/pub/OpenLinux/updates/1.2/006/RPMS The corresponding source code can be found at: ftp://ftp.caldera.com/pub/OpenLinux/updates/1.2/006/SRPMS The MD5 checksums (from the "md5sum" command) for these packages are:
http://www.caldera.com/tech-ref/security/
Data GeneralThis problem is fixed in revision R4.20MU04 of DG/UX. The following patches are available for earlier revisions: Revision Patch Number ----------------------------------- R4.20MU01 tcpip_R4.20MU01.p10 R4.20MU02 tcpip_R4.20MU02.p09 R4.20MU03 tcpip_R4.20MU03.p01 R4.11MU05 tcpip_R4.11MU05.p09 R4.12MU03 tcpip_R4.12MU03.p02 Digital Equipment CorporationDigital is investigating this problem.FreeBSD, Inc.We ship with INVQ not defined. This makes us resistent against the first vulnerability. This is true for all release after 2.2.0 (2.1.* releases are vulnerable but should be upgraded anyway). As we do not yet ship BIND 8, we are also not vulnerable to the 3rd vulnerability.We advise everyone to upgrade to BIND 4.9.7. Hewlett-Packard CompanySee Hewlett-Packard Security Bulletin "Security Vulnerability in BIND on HP-UX", HPSBUX9808-083, dated August 19, 1998, for details concerning the availability of patches.Hewlett Packard's HP-UX patches/Security Bulletins/Security patches are available via email and/or WWW (via the browser of your choice) on HP's Electronic Support Center (ESC). To subscribe to automatically receive future NEW HP Security Bulletins from the HP ESC Digest service via electronic mail, do the following: From your Web browser, access the URL: http://us-support.external.hp.com (US,Canada,Asia-Pacific, and Latin-America) http://europe-support.external.hp.com (Europe)
To report new security vulnerabilities, send email to security-alert@hp.com Please encrypt any exploit information using the security-alert PGP key, available from your local key server, or by sending a message with a -subject- (not body) of 'get key' (no quotes) to security-alert@hp.com. IBM CorporationThe version of bind shipped with AIX is vulnerable and the following APARs will be available soon:
AIX 4.1.x: IX76958 (fix for Topic 1 only)
AIX 4.2.x: IX76959 (fix for Topic 1 only)
AIX 4.3.x: IX76960 (fix for Topic 1 and 3 only)
AIX 4.3.x: IX76962 (fix for Topic 1, 2, and 3. This is bind 8.1.2.)
Until the official fixes are available, a temporary patch can be found
at:
ftp://aix.software.ibm.com/aix/efixes/security
File sum md5
====================================================================
named.415.tar.Z 64980 157 0e795380b84bf29385d2d946d10406cb
named.421.tar.Z 44963 157 15a9a006abf4a9d0a0d3210f16d619e5
named4.430.tar.Z 48236 115 8377b14f74e207707154a9677906f20a
named8.430.tar.Z 51175 160 e2db14b7055a7424078456bfbfd9bf2d
Detached PGP signatures are also available with a ".asc" extension.
IBM and AIX are registered trademarks of International Business Machines Corporation. Internet Software ConsortiumThe Internet Software Consortium has announced BIND version 8.1.2 and BIND version 4.9.7.If you are running BIND 8.1.1 or 8.1 you want to upgrade to 8.1.2. If you are still running BIND-4 rather than BIND-8, you need the security patches contained in 4.9.7. But, you should really just run BIND-8. The security fixes included in these releases fix a stack overrun that could occur if inverse query support was enabled, and a number of denial of service attacks where malformed packets could cause the server to crash. Links to the kits are available at: http://www.isc.org/new-bind.html. NEC CorporationTopic1 - Some systems are vulnerable. Patches will be available soon, especially for UX/4800 R11.x and R13.x.Topic2 - Some systems are vulnerable. Patches will be available soon after the release of bind-4.9.7, especially for UX/4800 R11.x and R13.x. Topic3 - We do not ship BIND 8 with our products so we are not vulnerable to this problem. Patches will be available from ftp://ftp.meshnet.or.jp/pub/48pub/security. The NetBSD ProjectThe first problem can be fixed in NetBSD 1.3, 1.3.1, and -current prior to 19980408 with the supplied BIND 4.9.6 patch. A patch will be made available for the second problem shortly (alternatively, upgrading to BIND 4.9.7 or 8.1.2 when available will also solve this problem.) NetBSD is not affected by the third problem.Red Hat Software, Inc.Red Hat fixes will be available at:Red Hat 5.0i386:rpm -Uvh ftp://ftp.redhat.com/updates/5.0/i386/bind-4.9.6-7.i386.rpm alpha: Red Hat 4.2i386:rpm -Uvh ftp://ftp.redhat.com/updates/4.2/i386/bind-4.9.6-1.1.i386.rpm alpha:
SPARC:
The Santa Cruz Operation, Inc.The following SCO products are vulnerable:
Binary versions of BIND 4.9.7 will be available shortly from the SCO ftp site: cover letter - ftp://ftp.sco.com/SSE/sse012.ltr
The fix includes binaries for the following SCO operating systems:
Silicon Graphics, Inc.Silicon Graphics Inc. issued Security Advisory, " IRIX BIND DNS Vulnerabilities," 19980603-02-PX, August 6, 1998.Patches are available via anonymous FTP and your service/support provider. The SGI anonymous FTP site is sgigate.sgi.com (204.94.209.1) or its mirror, ftp.sgi.com. Security information and patches can be found in the ~ftp/security and ~ftp/patches directories, respectfully. For subscribing to the wiretap mailing list and other SGI security related information, please refer to the Silicon Graphics Security Headquarters website located at: http://www.sgi.com/Support/security Sun Microsystems, Inc.Topic 1: Patches will be produced for Solaris 5.3, 5.4, 5.5, 5.5.1 and 5.6.Topic 2: Patches will be produced for Solaris 5.3, 5.4, 5.5, 5.5.1 and 5.6. Topic 3: Bug fix will be integrated in the upcoming release of Solaris. The CERT Coordination Center thanks Bob Halley and Paul Vixie of Vixie Enterprises, who provided most of the text of this advisory.
Reminder: This document is available from: http://www.cert.org/advisories/CA-1998-05.html CERT/CC Contact Information
Phone: +1 412-268-7090 (24-hour hotline) Fax: +1 412-268-6989 Postal address: CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends. Using encryptionWe strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from If you prefer to use DES, please call the CERT hotline for more information. Getting security informationCERT publications and other security information are available from our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY Conditions for use, disclaimers, and sponsorship information
Copyright 1998 Carnegie Mellon University. Revision History
Nov. 16, 1998 Added vendor information for Data General.
Aug. 21, 1998 Updated vendor informaton for HP and SGI.
June 19, 1998 Updated vendor informaton for SGI.
June 18, 1998 Added a pointer to more information in the UPDATES section.
May 21, 1998 Updates were made to the following portions of this advisory:
III. Solutions
Topic 1: Inverse Query Buffer Overrun in BIND 4.9 and BIND 8 Releases
1.C. What To Do
Fixing the Inverse Query Code, Bind 8 and Bind 4.9
Topic 2: Denial-of-Service Vulnerabilities in BIND 4.9 and BIND 8 Releases
2.C. What To Do
Topic 3: Denial-of-Service Vulnerability in BIND 8 Releases
3.C. What To Do
Fixing the Problem
Appendix A - Updated vendor information for Internet Software Consortium
Apr. 16, 1998 Appendix A - Updated vendor information for Caldera
Corporation.
|








