DNSSEC-Tools libval Security Bypass Vulnerability
BID:27998
Info
DNSSEC-Tools libval Security Bypass Vulnerability
| Bugtraq ID: | 27998 |
| Class: | Design Error |
| CVE: |
CVE-2008-1184 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
DNSSEC-Tools DNSSEC-Tools 1.3 DNSSEC-Tools DNSSEC-Tools 1.2 |
| Not Vulnerable: |
DNSSEC-Tools DNSSEC-Tools 1.3.2 |
Discussion
DNSSEC-Tools libval Security Bypass Vulnerability
DNSSEC-Tools is prone to a security-bypass vulnerability due to an error in the 'libval' DNSSEC validation library.
Attackers can exploit this issue to bypass DNSSEC checks in an application that uses the vulnerable library and to make the application accept forged DNS data; this may aid in further attacks.
This issue affects versions prior to DNSSEC-Tools 1.3.2.
DNSSEC-Tools is prone to a security-bypass vulnerability due to an error in the 'libval' DNSSEC validation library.
Attackers can exploit this issue to bypass DNSSEC checks in an application that uses the vulnerable library and to make the application accept forged DNS data; this may aid in further attacks.
This issue affects versions prior to DNSSEC-Tools 1.3.2.
Exploit / POC
DNSSEC-Tools libval Security Bypass Vulnerability
An exploit is not required; an attacker could use readily available tools to introduce new DNS records.
An exploit is not required; an attacker could use readily available tools to introduce new DNS records.
Solution / Fix
DNSSEC-Tools libval Security Bypass Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
References
DNSSEC-Tools libval Security Bypass Vulnerability
References:
References:
- DNSSEC-Tools Homepage (DNSSEC-Tools)
- DNSSEC-Tools SVN Revision 3872 (DNSSEC-Tools)