DeleGate DNS Response Denial Of Service Vulnerability
BID:17691
Info
DeleGate DNS Response Denial Of Service Vulnerability
| Bugtraq ID: | 17691 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2006 12:00AM |
| Updated: | Apr 26 2006 07:31PM |
| Credit: | This issue was discovered by the PROTOS DNS Test Suite, which was developed by the Oulu University Secure Programming Group (OUSPG). |
| Vulnerable: |
DeleGate DeleGate 9.0.5 DeleGate DeleGate 9.0.4 DeleGate DeleGate 9.0.3 DeleGate DeleGate 9.0.2 DeleGate DeleGate 9.0.1 DeleGate DeleGate 9.0 DeleGate DeleGate 8.11.5 DeleGate DeleGate 8.11.4 DeleGate DeleGate 8.11.3 DeleGate DeleGate 8.11.2 DeleGate DeleGate 8.11.1 DeleGate DeleGate 8.11 DeleGate DeleGate 8.10.6 DeleGate DeleGate 8.10.5 DeleGate DeleGate 8.10.4 DeleGate DeleGate 8.10.3 DeleGate DeleGate 8.10.2 DeleGate DeleGate 8.10.1 DeleGate DeleGate 8.10 DeleGate DeleGate 8.9.6 DeleGate DeleGate 8.9.5 DeleGate DeleGate 8.9.4 DeleGate DeleGate 8.9.3 DeleGate DeleGate 8.9.2 DeleGate DeleGate 8.9.1 DeleGate DeleGate 8.9 DeleGate DeleGate 8.5 .0 DeleGate DeleGate 8.4 .0 DeleGate DeleGate 8.3.4 DeleGate DeleGate 8.3.3 DeleGate DeleGate 7.9.11 DeleGate DeleGate 7.8.2 DeleGate DeleGate 7.8.1 DeleGate DeleGate 7.8 .0 DeleGate DeleGate 7.7.1 DeleGate DeleGate 7.7 .0 |
| Not Vulnerable: |
DeleGate DeleGate 9.0.6 DeleGate DeleGate 8.11.6 |
Discussion
DeleGate DNS Response Denial Of Service Vulnerability
DeleGate is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed DNS responses.
An attacker can exploit this issue to crash the affected service, effectively denying service to legitimate users.
The vendor has addressed this issue in versions 8.11.6 and 9.0.6; earlier versions are vulnerable.
DeleGate is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed DNS responses.
An attacker can exploit this issue to crash the affected service, effectively denying service to legitimate users.
The vendor has addressed this issue in versions 8.11.6 and 9.0.6; earlier versions are vulnerable.
Exploit / POC
DeleGate DNS Response Denial Of Service Vulnerability
The PROTOS DNS Test Suite, which was developed by the Oulu University Secure Programming Group (OUSPG), may be used to trigger this issue.
The PROTOS DNS Test Suite, which was developed by the Oulu University Secure Programming Group (OUSPG), may be used to trigger this issue.
Solution / Fix
DeleGate DNS Response Denial Of Service Vulnerability
Solution:
The vendor has released versions 8.11.6 and 9.0.6 of DeleGate to address this issue.
DeleGate DeleGate 7.7 .0
DeleGate DeleGate 7.7.1
DeleGate DeleGate 7.8 .0
DeleGate DeleGate 7.8.1
DeleGate DeleGate 7.8.2
DeleGate DeleGate 7.9.11
DeleGate DeleGate 8.10
DeleGate DeleGate 8.10.1
DeleGate DeleGate 8.10.2
DeleGate DeleGate 8.10.3
DeleGate DeleGate 8.10.4
DeleGate DeleGate 8.10.5
DeleGate DeleGate 8.10.6
DeleGate DeleGate 8.11
DeleGate DeleGate 8.11.1
DeleGate DeleGate 8.11.2
DeleGate DeleGate 8.11.3
DeleGate DeleGate 8.11.4
DeleGate DeleGate 8.11.5
DeleGate DeleGate 8.3.3
DeleGate DeleGate 8.3.4
DeleGate DeleGate 8.4 .0
DeleGate DeleGate 8.5 .0
DeleGate DeleGate 8.9
DeleGate DeleGate 8.9.1
DeleGate DeleGate 8.9.2
DeleGate DeleGate 8.9.3
DeleGate DeleGate 8.9.4
DeleGate DeleGate 8.9.5
DeleGate DeleGate 8.9.6
Solution:
The vendor has released versions 8.11.6 and 9.0.6 of DeleGate to address this issue.
DeleGate DeleGate 7.7 .0
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 7.7.1
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 7.8 .0
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 7.8.1
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 7.8.2
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 7.9.11
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.10
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.10.1
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.10.2
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.10.3
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.10.4
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.10.5
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.10.6
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.11
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.11.1
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.11.2
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.11.3
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.11.4
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.11.5
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.3.3
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.3.4
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.4 .0
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.5 .0
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.9
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.9.1
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.9.2
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.9.3
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.9.4
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.9.5
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
DeleGate DeleGate 8.9.6
-
DeleGate delegate8.11.6.tar.gz
ftp://ftp.delegate.org/pub/DeleGate/delegate8.11.6.tar.gz
References
DeleGate DNS Response Denial Of Service Vulnerability
References:
References:
- Delegate Homepage (Yutaka Sato)
- History of DeleGate Updates (DeleGate)
- NISCC Vulnerability Advisory 144154/NISCC/DNS (NISCC)
- NISCC Vulnerability Advisory 144154/NISCC/DNS - Vulnerability Issues in Implemen (NISCC)