Symantec Enterprise Firewall DNSD DNS Cache Poisoning Vulnerability
BID:10557
Info
Symantec Enterprise Firewall DNSD DNS Cache Poisoning Vulnerability
| Bugtraq ID: | 10557 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2004 12:00AM |
| Updated: | Jun 15 2004 12:00AM |
| Credit: | This issue was disclosed to Bugtraq by fryxar <[email protected]>. |
| Vulnerable: |
Symantec Gateway Security 5400 2.0.1 Symantec Gateway Security 5400 2.0 Symantec Gateway Security 5310 1.0 Symantec Gateway Security 5300 1.0 Symantec Gateway Security 5200 1.0 Symantec Gateway Security 5110 1.0 Symantec Enterprise Firewall 8.0 Solaris Symantec Enterprise Firewall 8.0 NT/2000 Symantec Enterprise Firewall 8.0 Symantec Enterprise Firewall 7.0.4 Solaris Symantec Enterprise Firewall 7.0.4 NT/2000 |
| Not Vulnerable: | |
Discussion
Symantec Enterprise Firewall DNSD DNS Cache Poisoning Vulnerability
It is reported that dnsd is prone to a cache poisoning vulnerability.
Dnsd does not ensure that the data returned from a remote DNS server contains related information about the requested records.
An attacker could exploit this vulnerability to deny service to legitimate users by redirecting traffic to inappropriate hosts. Man-in-the-middle attacks, impersonation of sites, and other attacks may be possible.
It is reported that dnsd is prone to a cache poisoning vulnerability.
Dnsd does not ensure that the data returned from a remote DNS server contains related information about the requested records.
An attacker could exploit this vulnerability to deny service to legitimate users by redirecting traffic to inappropriate hosts. Man-in-the-middle attacks, impersonation of sites, and other attacks may be possible.
Exploit / POC
Symantec Enterprise Firewall DNSD DNS Cache Poisoning Vulnerability
A proof of concept exploit was provided by fryxar <[email protected]>.
A proof of concept exploit was provided by fryxar <[email protected]>.
Solution / Fix
Symantec Enterprise Firewall DNSD DNS Cache Poisoning Vulnerability
Solution:
Symantec has released security response advisory SYM04-010 along with hotfixes dealing with this issue. Customers are advised to obtain patches through Enterprise Product Support. Please see the referenced web advisory for more information.
Symantec has released further hotfixes and a document (Latest hotfixes for the Symantec DNSd cache-poisoning vulnerability) to address this issue. It is reported that the previous fixes did not completely address the issue for certain customers. Please see the referenced document for further information.
Symantec Gateway Security 5200 1.0
Symantec Gateway Security 5300 1.0
Symantec Gateway Security 5110 1.0
Symantec Gateway Security 5310 1.0
Symantec Gateway Security 5400 2.0
Symantec Gateway Security 5400 2.0.1
Symantec Enterprise Firewall 7.0.4 Solaris
Symantec Enterprise Firewall 7.0.4 NT/2000
Symantec Enterprise Firewall 8.0
Symantec Enterprise Firewall 8.0 Solaris
Symantec Enterprise Firewall 8.0 NT/2000
Solution:
Symantec has released security response advisory SYM04-010 along with hotfixes dealing with this issue. Customers are advised to obtain patches through Enterprise Product Support. Please see the referenced web advisory for more information.
Symantec has released further hotfixes and a document (Latest hotfixes for the Symantec DNSd cache-poisoning vulnerability) to address this issue. It is reported that the previous fixes did not completely address the issue for certain customers. Please see the referenced document for further information.
Symantec Gateway Security 5200 1.0
-
Symantec SG7000-20040907-00-Linux-SGS1.0.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_gate way_security/1.0/updates/SG7000-20040907-00-Linux-SGS1.0.tgz
Symantec Gateway Security 5300 1.0
-
Symantec SG7000-20040907-00-Linux-SGS1.0.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_gate way_security/1.0/updates/SG7000-20040907-00-Linux-SGS1.0.tgz
Symantec Gateway Security 5110 1.0
-
Symantec SG7000-20040907-00-Linux-SGS1.0.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_gate way_security/1.0/updates/SG7000-20040907-00-Linux-SGS1.0.tgz
Symantec Gateway Security 5310 1.0
-
Symantec SG7000-20040907-00-Linux-SGS1.0.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_gate way_security/1.0/updates/SG7000-20040907-00-Linux-SGS1.0.tgz
Symantec Gateway Security 5400 2.0
-
Symantec PKG-SG8000-20040907-00-Linux-20.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_gate way_security/2.0/updates/PKG-SG8000-20040907-00-Linux-20.tgz
Symantec Gateway Security 5400 2.0.1
-
Symantec PKG-SG8000-20040907-00-Linux.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_gate way_security/2.0.1/updates/PKG-SG8000-20040907-00-Linux.tgz
Symantec Enterprise Firewall 7.0.4 Solaris
-
Symantec SG7000-20040907-00-sol-3des.zip
3DES
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_ente rprise_firewall/704/updates/solaris/SG7000-20040907-00-sol-3des.zip -
Symantec SG7000-20040907-00-sol-des.zip
DES
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_ente rprise_firewall/704/updates/solaris/SG7000-20040907-00-sol-des.zip
Symantec Enterprise Firewall 7.0.4 NT/2000
-
Symantec SG7000-20040907-00-win-3des.zip
3DES
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_ente rprise_firewall/704/updates/windows/SG7000-20040907-00-win-3des.zip -
Symantec SG7000-20040907-00-win-des.zip
DES
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_ente rprise_firewall/704/updates/windows/SG7000-20040907-00-win-des.zip
Symantec Enterprise Firewall 8.0
-
Symantec PKG-SG8000-20040907-00-Windows.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_ente rprise_firewall/8.0/updates/windows/PKG-SG8000-20040907-00-Windows.tgz
Symantec Enterprise Firewall 8.0 Solaris
-
Symantec PKG-SG8000-20040907-00-Solaris.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_ente rprise_firewall/8.0/updates/solaris/PKG-SG8000-20040907-00-Solaris.tgz -
Symantec PKG-SG8000-20040907-00-Windows.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_ente rprise_firewall/8.0/updates/windows/PKG-SG8000-20040907-00-Windows.tgz
Symantec Enterprise Firewall 8.0 NT/2000
-
Symantec PKG-SG8000-20040907-00-Windows.tgz
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_ente rprise_firewall/8.0/updates/windows/PKG-SG8000-20040907-00-Windows.tgz
References
Symantec Enterprise Firewall DNSD DNS Cache Poisoning Vulnerability
References:
References:
- Latest hotfixes for the Symantec DNSd cache-poisoning vulnerability (Symantec)
- SYM04-010 - Symantec Gateway Security Products DNS Cache Poisoning Vulnerability (Symantec)
- Symantec Enterprise Firewall Product Homepage (Symantec)
- Re: Symantec Enterprise Firewall DNSD cache poisoning Vulnerability (Peter Jelver
) - Symantec Enterprise Firewall DNSD cache poisoning Vulnerability (fryxar
)