Executive Summary

Summary
Title Unexpected ACL Behavior in BIND 9.7.2
Informations
Name VU#784855 First vendor Publication 2010-09-30
Vendor VU-CERT Last vendor Modification 2010-09-30
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Vulnerability Note VU#784855

Unexpected ACL Behavior in BIND 9.7.2

Overview

A flaw exists in BIND 9.7.2 through 9.7.2-P1 pertaining to how an ACL is applied.

I. Description

There is a flaw in BIND 9.7.2 through 9.7.2-P1 where the wrong ACL is applied. This flaw could allow access to a cache via recursion even though the ACL disallowed it. This bug is primarily a risk to operators running both authoritative and recursive DNS on the same BIND server in the same view.

II. Impact

A loss of confidentiality in cache data exists.

III. Solution

Upgrade to BIND 9.7.2-P2

Vendor Information

VendorStatusDate NotifiedDate Updated
Internet Systems ConsortiumAffected2010-09-282010-09-30

References

https://lists.isc.org/pipermail/bind-announce/2010-September/000655.html
http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.html

Credit

This document was written by Jared Allar.

Other Information

Date Public:2010-09-28
Date First Published:2010-09-30
Date Last Updated:2010-09-30
CERT Advisory: 
CVE-ID(s):CVE-2010-0218
NVD-ID(s):CVE-2010-0218
US-CERT Technical Alerts: 
Metric:0.01
Document Revision:7

Original Source

Url : http://www.kb.cert.org/vuls/id/784855

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2

OpenVAS Exploits

Date Description
2010-09-30 Name : ISC BIND Denial Of Service and Security Bypass Vulnerability
File : nvt/gb_bind_43573.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
68270 ISC BIND ACL Application Weakness Cache Recursion Access Restriction Bypass

Nessus® Vulnerability Scanner

Date Description
2010-10-06 Name : The remote name server is affected by multiple vulnerabilities.
File : bind9_972_p2.nasl - Type : ACT_GATHER_INFO