Multiple Vendors BIND 'inet_network()' Off-by-One Buffer Overflow Vulnerability
BID:27283
Info
Multiple Vendors BIND 'inet_network()' Off-by-One Buffer Overflow Vulnerability
| Bugtraq ID: | 27283 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0122 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2008 12:00AM |
| Updated: | Feb 11 2016 07:31AM |
| Credit: | Bjoern A. Zeeb and Nate Eldredge discovered this issue. |
| Vulnerable: |
Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE openSUSE 10.3 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_sparc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE Linux Enterprise Server RT Solution 10 0 S.u.S.E. openSUSE 10.2 S.u.S.E. openSUSE 10.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server ISC BIND 9.5 a2 ISC BIND 9.5 a1 ISC BIND 9.4.1 -P1 ISC BIND 9.4.1 ISC BIND 9.4 rc2 ISC BIND 9.4 rc1 ISC BIND 9.4 b4 ISC BIND 9.4 b3 ISC BIND 9.4 b3 ISC BIND 9.4 b2 ISC BIND 9.4 b1 ISC BIND 9.4 a6 ISC BIND 9.4 a5 ISC BIND 9.4 a4 ISC BIND 9.4 a3 ISC BIND 9.4 a2 ISC BIND 9.4 a1 ISC BIND 9.4 ISC BIND 9.3.4 ISC BIND 9.3.3 rc3 ISC BIND 9.3.3 rc2 ISC BIND 9.3.3 rc1 ISC BIND 9.3.3 b1 ISC BIND 9.3.3 b ISC BIND 9.3.3 ISC BIND 9.3.2 -P2 ISC BIND 9.3.2 -P1 ISC BIND 9.3.2 ISC BIND 9.3.1 ISC BIND 9.3 ISC BIND 9.2.8 ISC BIND 9.2.7 rc3 ISC BIND 9.2.7 rc2 ISC BIND 9.2.7 rc1 ISC BIND 9.2.7 b1 ISC BIND 9.2.7 ISC BIND 9.2.6 -P2 ISC BIND 9.2.6 -P1 ISC BIND 9.2.6 ISC BIND 9.2.5 ISC BIND 9.2.4 ISC BIND 9.2.3 ISC BIND 9.2.2 ISC BIND 9.2.1 ISC BIND 9.2 ISC BIND 9.1.3 ISC BIND 9.1.2 ISC BIND 9.1.1 ISC BIND 9.1 ISC BIND 9.0.1 ISC BIND 9.0 ISC BIND 8.4.7 -P1 ISC BIND 8.4.7 ISC BIND 8.4.6 ISC BIND 8.4.5 ISC BIND 8.4.4 ISC BIND 8.4.3 ISC BIND 8.4.2 ISC BIND 8.4.1 ISC BIND 8.4 ISC BIND 8.3.7 ISC BIND 8.3.6 ISC BIND 8.3.5 ISC BIND 8.3.4 ISC BIND 8.3.3 ISC BIND 8.3.2 ISC BIND 8.3.1 ISC BIND 8.3 .0 ISC BIND 8.2.7 ISC BIND 8.2.6 ISC BIND 8.2.5 ISC BIND 8.2.4 ISC BIND 8.2.3 Beta ISC BIND 8.2.3 ISC BIND 8.2.2 p7 ISC BIND 8.2.2 p6 ISC BIND 8.2.2 p5 ISC BIND 8.2.2 p4 ISC BIND 8.2.2 p3 ISC BIND 8.2.2 p2 ISC BIND 8.2.2 p1 ISC BIND 8.2.2 ISC BIND 8.2.1 ISC BIND 8.2 ISC BIND 8.1.2 ISC BIND 8.1.1 ISC BIND 8.1 ISC BIND 9.5.0b1 ISC BIND 9.5.0a7 ISC BIND 9.5.0a6 ISC BIND 9.5.0a5 ISC BIND 9.5.0a4 ISC BIND 9.5.0a3 IBM AIX 6.1 IBM AIX 5.3 IBM AIX 5.2 FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 7.0 -RELENG FreeBSD FreeBSD 7.0 -PRERELEASE FreeBSD FreeBSD 6.3 -RELENG FreeBSD FreeBSD 6.2 -RELENG FreeBSD FreeBSD 6.2 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 14.0 Avaya CMS Server 13.1 |
| Not Vulnerable: |
ISC BIND 9.4.3 ISC BIND 9.3.5 ISC BIND 9.5.0b2 |
Discussion
Multiple Vendors BIND 'inet_network()' Off-by-One Buffer Overflow Vulnerability
Multiple applications that use the 'libbind' BIND library are prone to an off-by-one buffer-overflow vulnerability because the 'inet_network()' function fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts may crash applications, denying service to legitimate users.
Multiple applications that use the 'libbind' BIND library are prone to an off-by-one buffer-overflow vulnerability because the 'inet_network()' function fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts may crash applications, denying service to legitimate users.
Exploit / POC
Multiple Vendors BIND 'inet_network()' Off-by-One Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Vendors BIND 'inet_network()' Off-by-One Buffer Overflow Vulnerability
Solution:
Advisories and fixes are available. Please see the references for details on applying fixes for specific products.
FreeBSD FreeBSD 6.2
Solution:
Advisories and fixes are available. Please see the references for details on applying fixes for specific products.
FreeBSD FreeBSD 6.2
-
FreeBSD libc.patch
http://security.freebsd.org/patches/SA-08:02/libc.patch
References
Multiple Vendors BIND 'inet_network()' Off-by-One Buffer Overflow Vulnerability
References:
References:
- BIND: buffer overflow in inet_network() (Internet Systems Consortium)
- FreeBSD Homepage (FreeBSD)
- ASA-2008-244 Security Vulnerability in inet_network() Library Routine May Allow (Avaya)
- IZ15564: POTENTIAL SECURITY ISSUE IN LIBC (IBM)
- IZ15566: POTENTIAL SECURITY ISSUE IN LIBC (IBM)
- IZ15566: POTENTIAL SECURITY ISSUE IN LIBC (IBM)
- IZ15567: POTENTIAL SECURITY ISSUE IN LIBC (IBM)
- RHSA-2008:0300-16 bind security, bug fix, and enhancement update (Red Hat)
- Solution 238493: Security Vulnerability in inet_network() Library Routine May Al (Sun Microsystems)
- UPDATE AIX libc inet_network buffer overflow (IBM)
- VU#203611 BIND version 8 generates cryptographically weak DNS query identifiers (US-CERT)
- Vulnerability Note VU#203611 inet_network() off-by-one buffer overflow (US-CERT)