ISC BIND Q_UseDNS Remote Buffer Overflow Vulnerability
BID:12364
Info
ISC BIND Q_UseDNS Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 12364 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-0033 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Joao Damas of the Internet Systems Consortium is credited with the disclosure of this issue. |
| Vulnerable: |
SCO Open Server 6.0 SCO Open Server 5.0.7 SCO Open Server 5.0.6 ISC BIND 8.4.5 ISC BIND 8.4.4 Astaro Security Linux 4.0 17 Astaro Security Linux 4.0 16 Astaro Security Linux 4.0 08 Astaro Security Linux 3.217 Astaro Security Linux 3.2 16 Astaro Security Linux 3.2 15 Astaro Security Linux 3.2 12 Astaro Security Linux 3.2 11 Astaro Security Linux 3.2 10 Astaro Security Linux 3.2 00 Astaro Security Linux 2.0 30 Astaro Security Linux 2.0 27 Astaro Security Linux 2.0 26 Astaro Security Linux 2.0 25 Astaro Security Linux 2.0 24 Astaro Security Linux 2.0 23 Astaro Security Linux 2.0 16 |
| Not Vulnerable: |
ISC BIND 8.4.6 |
Discussion
ISC BIND Q_UseDNS Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects BIND. This issue is due to a failure of the application to properly validate the length of user-supplied input prior to copying it into static process buffers.
An attacker may leverage this issue to trigger a denial of service condition. It should be noted that this issue may also facilitate code execution with the privileges of the affected utility, however this is not confirmed.
A remote buffer overflow vulnerability affects BIND. This issue is due to a failure of the application to properly validate the length of user-supplied input prior to copying it into static process buffers.
An attacker may leverage this issue to trigger a denial of service condition. It should be noted that this issue may also facilitate code execution with the privileges of the affected utility, however this is not confirmed.
Exploit / POC
ISC BIND Q_UseDNS Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ISC BIND Q_UseDNS Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Astaro Security Linux has released Up2Date 5.103 dealing with this issue. Please see the referenced notice in the reference section for more information.
SCO has released advisory SCOSA-2006.1, along with fixes to address this issue in SCO OpenServer 5.0.6, 5.0.7, and 6.0.0. Please see the referenced advisory for further information.
SCO Open Server 5.0.6
SCO Open Server 5.0.7
SCO Open Server 6.0
ISC BIND 8.4.4
ISC BIND 8.4.5
Solution:
The vendor has released an upgrade dealing with this issue.
Astaro Security Linux has released Up2Date 5.103 dealing with this issue. Please see the referenced notice in the reference section for more information.
SCO has released advisory SCOSA-2006.1, along with fixes to address this issue in SCO OpenServer 5.0.6, 5.0.7, and 6.0.0. Please see the referenced advisory for further information.
SCO Open Server 5.0.6
-
SCO p531004.507_vol.tar
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.1/p531004.507_vol. tar
SCO Open Server 5.0.7
-
SCO p531004.507_vol.tar
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.1/p531004.507_vol. tar
SCO Open Server 6.0
-
SCO p531004.600_vol.tar
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.1/p531004.600_vol. tar
ISC BIND 8.4.4
-
ISC BIND 8.4.6
http://www.isc.org/index.pl?/sw/bind/
ISC BIND 8.4.5
-
ISC BIND 8.4.6
http://www.isc.org/index.pl?/sw/bind/
References
ISC BIND Q_UseDNS Remote Buffer Overflow Vulnerability
References:
References:
- BIND Security (ISC)
- ISC BIND Homepage (ISC)
- Up2Date 5.103 (Astaro)
- Vulnerability Note VU#327633 - BIND 8.4.4 and 8.4.5 vulnerable to buffer overflo (US-CERT)