Executive Summary
| Summary | |
|---|---|
| Title | BIND DNS Nameserver, DNSSEC validation Vulnerability |
| Informations | |||
|---|---|---|---|
| Name | VU#418861 | First vendor Publication | 2009-12-01 |
| Vendor | VU-CERT | Last vendor Modification | 2010-01-19 |
| Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:H/Au:N/C:N/I:P/A:N) | |||
|---|---|---|---|
| Cvss Base Score | 2.6 | Attack Range | Network |
| Cvss Impact Score | 2.9 | Attack Complexity | High |
| Cvss Expoit Score | 4.9 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Vulnerability Note VU#418861BIND DNS Nameserver, DNSSEC validation VulnerabilityOverviewA vulnerability exists in the way BIND 9 handles recursive client queries that may cause additional records to be added to its cache.I. DescriptionBIND 9 contains a vulnerability in the way recursive client queries are handled. According to ISC:A nameserver with DNSSEC validation enabled may incorrectly add unauthenticated records to its cache that are received during the resolution of a recursive client query with checking disabled (CD), or when the nameserver internally triggers a query for missing records for recursive name resolution. Cached records can be returned in response to subsequent client queries with or without requesting DNSSEC records (DO). In addition, some of them can be returned to queries with or without checking disabled (CD). II. ImpactAn attacker may be able to manipulate cache data and perform DNS Cache Poisoning.III. SolutionUpgradeBIND should be upgraded to version 9.4.3-P5, 9.5.2-P2 or 9.6.1-P3. Systems Affected
ReferencesCreditISC credits Michael Sinatra, UC Berkeley with finding this issue. This document was written by Chris Taschner. Other Information
|
Original Source
| Url : http://www.kb.cert.org/vuls/id/418861 |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:7459 | |||
| Oval ID: | oval:org.mitre.oval:def:7459 | ||
| Title: | Security Vulnerability in BIND DNS Software Shipped With Solaris May Allow DNS Cache Poisoning | ||
| Description: | Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-4022 |
Version: | 3 |
| Platform(s): | Sun Solaris 9 Sun Solaris 10 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:7261 | |||
| Oval ID: | oval:org.mitre.oval:def:7261 | ||
| Title: | HP-UX Running BIND, Remote Denial of Service (DoS), Unauthorized Disclosure of Information | ||
| Description: | Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-4022 |
Version: | 3 |
| Platform(s): | HP-UX 11 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:11745 | |||
| Oval ID: | oval:org.mitre.oval:def:11745 | ||
| Title: | Vulnerability with DNSSEC validation enabled in BIND. | ||
| Description: | Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-4022 |
Version: | 3 |
| Platform(s): | IBM AIX 6.1 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:10821 | |||
| Oval ID: | oval:org.mitre.oval:def:10821 | ||
| Title: | Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438. | ||
| Description: | Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-4022 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 60493 | ISC BIND DNSSEC Recursive Query Additional Section Cache Poisoning |

VU#418861
(Medium)
(Low)






