Executive Summary

Summary
Title NSD vulnerable to one-byte overflow
Informations
Name VU#710316 First vendor Publication 2009-05-20
Vendor VU-CERT Last vendor Modification 2009-06-01
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Vulnerability Note VU#710316

NSD vulnerable to one-byte overflow

Overview

A vulnerability exists in the way NSD processes certain types of packets that may lead to a one-byte buffer overflow.

I. Description

Name server daemon (NSD) is an open source name server developed by NLnet Labs. NSD contains an off-by-one error that can cause a one-byte buffer overflow when certain packets are processed. The vulnerability exits in the packet_read_query_section() function in packet.c in versions 3.x and in the process_query_section() function in query.c in versions 2.x.

Note that this issue affects NSD versions 2.0.0 through 3.2.1.

II. Impact

A remote, unauthenticated attacker may be able to cause the DNS software to crash resulting in a denial-of-service condition.

III. Solution

Apply patch


NLnet Labs has released NSD version 3.2.2 and patches for versions 3.2.1 and 2.3.7. More information and links to these patches can be found in NLnet Labs NSD Announcement.

Users are encouraged to check with their vendor to determine the appropriate patch or update to apply.

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown2009-05-192009-05-19
ACCESSUnknown2009-05-192009-05-19
Alcatel-LucentUnknown2009-05-192009-05-19
Apple Computer, Inc.Not Vulnerable2009-05-192009-05-20
AT&TUnknown2009-05-192009-05-19
Avaya, Inc.Unknown2009-05-192009-05-19
Barracuda NetworksUnknown2009-05-192009-05-19
Belkin, Inc.Unknown2009-05-192009-05-19
Borderware TechnologiesUnknown2009-05-192009-05-19
BroUnknown2009-05-192009-05-19
Charlotte's Web NetworksUnknown2009-05-192009-05-19
Check Point Software TechnologiesUnknown2009-05-192009-05-19
Cisco Systems, Inc.Unknown2009-05-192009-05-19
ClavisterUnknown2009-05-192009-05-19
Computer AssociatesNot Vulnerable2009-05-192009-05-22
Computer Associates eTrust Security ManagementNot Vulnerable2009-05-192009-05-22
Conectiva Inc.Unknown2009-05-192009-05-19
Cray Inc.Not Vulnerable2009-05-192009-05-20
Debian GNU/LinuxVulnerable2009-05-192009-05-20
DragonFly BSD ProjectUnknown2009-05-192009-05-19
EMC CorporationUnknown2009-05-192009-05-19
Engarde Secure LinuxUnknown2009-05-192009-05-19
Enterasys NetworksUnknown2009-05-192009-05-19
EricssonNot Vulnerable2009-05-192009-05-20
eSoft, Inc.Unknown2009-05-192009-05-19
Extreme NetworksNot Vulnerable2009-05-192009-05-22
F5 Networks, Inc.Unknown2009-05-192009-05-19
Fedora ProjectUnknown2009-05-192009-05-19
Force10 Networks, Inc.Unknown2009-05-192009-05-19
Fortinet, Inc.Unknown2009-05-192009-05-19
Foundry Networks, Inc.Unknown2009-05-192009-05-19
FreeBSD, Inc.Unknown2009-05-192009-05-19
Gentoo LinuxNot Vulnerable2009-05-192009-05-22
Global Technology AssociatesUnknown2009-05-192009-05-19
Hewlett-Packard CompanyUnknown2009-05-192009-05-19
HitachiUnknown2009-05-192009-05-19
IBM CorporationUnknown2009-05-192009-05-19
IBM eServerUnknown2009-05-192009-05-19
Internet Security Systems, Inc.Unknown2009-05-192009-05-19
IntotoUnknown2009-05-192009-05-19
IP FilterUnknown2009-05-192009-05-19
Juniper Networks, Inc.Unknown2009-05-192009-05-19
Luminous NetworksUnknown2009-05-192009-05-19
m0n0wallUnknown2009-05-192009-05-19
Mandriva S. A.Unknown2009-05-192009-05-19
McAfeeUnknown2009-05-192009-05-19
MontaVista Software, Inc.Unknown2009-05-192009-05-19
Multitech, Inc.Unknown2009-05-192009-05-19
NEC CorporationUnknown2009-05-192009-05-19
NetAppUnknown2009-05-192009-05-19
NetBSDUnknown2009-05-192009-05-19
netfilterUnknown2009-05-192009-05-19
NLnet LabsUnknown2009-05-282009-05-28
NokiaUnknown2009-05-192009-05-19
Nortel Networks, Inc.Unknown2009-05-192009-05-19
Novell, Inc.Unknown2009-05-192009-05-19
OpenBSDUnknown2009-05-192009-05-19
Openwall GNU/*/LinuxUnknown2009-05-192009-05-19
PePLinkNot Vulnerable2009-05-192009-05-20
Process SoftwareUnknown2009-05-192009-05-19
Q1 LabsNot Vulnerable2009-05-192009-06-01
QNX, Software Systems, Inc.Unknown2009-05-192009-05-19
QuaggaUnknown2009-05-192009-05-19
RadWare, Inc.Unknown2009-05-192009-05-19
Red Hat, Inc.Not Vulnerable2009-05-192009-05-20
Redback Networks, Inc.Unknown2009-05-192009-05-19
SafeNetNot Vulnerable2009-05-192009-05-22
Secureworx, Inc.Unknown2009-05-192009-05-19
Silicon Graphics, Inc.Unknown2009-05-192009-05-19
Slackware Linux Inc.Unknown2009-05-192009-05-19
SmoothWallUnknown2009-05-192009-05-19
SnortUnknown2009-05-192009-05-19
Soapstone NetworksUnknown2009-05-192009-05-19
Sony CorporationUnknown2009-05-192009-05-19
SourcefireUnknown2009-05-192009-05-19
StonesoftUnknown2009-05-192009-05-19
Sun Microsystems, Inc.Not Vulnerable2009-05-192009-05-20
SUSE LinuxUnknown2009-05-192009-05-19
SymantecUnknown2009-05-192009-05-19
The SCO GroupNot Vulnerable2009-05-192009-05-20
TippingPoint, Technologies, Inc.Unknown2009-05-192009-05-19
TurbolinuxUnknown2009-05-192009-05-19
U4EA Technologies, Inc.Unknown2009-05-192009-05-19
UbuntuUnknown2009-05-192009-05-19
UnisysUnknown2009-05-192009-05-19
VyattaUnknown2009-05-192009-05-19
Watchguard Technologies, Inc.Unknown2009-05-192009-05-19
Wind River Systems, Inc.Unknown2009-05-192009-05-19
ZyXELUnknown2009-05-192009-05-19

References


http://www.nlnetlabs.nl/publications/NSD_vulnerability_announcement.html

Credit

This issue was reported in NLnet Labs NSD Announcement.

This document was written by Chris Taschner.

Other Information

Date Public:2009-05-18
Date First Published:2009-05-20
Date Last Updated:2009-06-01
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:8.40
Document Revision:10

Original Source

Url : http://www.kb.cert.org/vuls/id/710316

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-17 12:08:08
  • Multiple Updates
2013-02-06 19:08:32
  • Multiple Updates