Mandrake Bind 9 Package Insecure File Permissions Vulnerability
BID:3848
Info
Mandrake Bind 9 Package Insecure File Permissions Vulnerability
| Bugtraq ID: | 3848 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 08 2002 12:00AM |
| Updated: | Jan 08 2002 12:00AM |
| Credit: | This vulnerability was announced in a Mandrake Security Advisory on January 8, 2002. |
| Vulnerable: |
Mandriva Linux Mandrake 8.1 ia64 Mandriva Linux Mandrake 8.1 Mandriva Linux Mandrake 8.0 ppc Mandriva Linux Mandrake 8.0 |
| Not Vulnerable: | |
Discussion
Mandrake Bind 9 Package Insecure File Permissions Vulnerability
The Berkeley Internet Name Daemon (Bind) is a freely available, open source name server daemon. It is maintained by the Internet Software Consortium (ISC). Bind is commonly used on Linux and Unix Operating Systems.
The implementation of BIND 9 included with Mandrake does not use secure permissions on files containing sensitive information. Under some circumstances, it may be possible for a local user to read the contents of the /etc/rndc.conf file, which contains sensitive information such as cryptographic passphrases and domain authority information. This permissions problem also applies to the /etc/rndc.key file. Additionally, users may also execute the rndc-confgen and rndc programs, which could present potential security problems such as the generation of malicious DNS configuration files.
The Berkeley Internet Name Daemon (Bind) is a freely available, open source name server daemon. It is maintained by the Internet Software Consortium (ISC). Bind is commonly used on Linux and Unix Operating Systems.
The implementation of BIND 9 included with Mandrake does not use secure permissions on files containing sensitive information. Under some circumstances, it may be possible for a local user to read the contents of the /etc/rndc.conf file, which contains sensitive information such as cryptographic passphrases and domain authority information. This permissions problem also applies to the /etc/rndc.key file. Additionally, users may also execute the rndc-confgen and rndc programs, which could present potential security problems such as the generation of malicious DNS configuration files.
Exploit / POC
Mandrake Bind 9 Package Insecure File Permissions Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mandrake Bind 9 Package Insecure File Permissions Vulnerability
Solution:
Updates available:
Mandriva Linux Mandrake 8.0 ppc
Mandriva Linux Mandrake 8.0
Mandriva Linux Mandrake 8.1 ia64
Solution:
Updates available:
Mandriva Linux Mandrake 8.0 ppc
-
Mandrake 8.0 ppc bind-9.1.1-1.1mdk.ppc.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/ppc/8.0/RPMS/bind-9.1.1-1 .1mdk.ppc.rpm -
Mandrake 8.0 ppc bind-devel-9.1.1-1.1mdk.ppc.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/ppc/8.0/RPMS/bind-devel-9 .1.1-1.1mdk.ppc.rpm -
Mandrake 8.0 ppc bind-utils-9.1.1-1.1mdk.ppc.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/ppc/8.0/RPMS/bind-utils-9 .1.1-1.1mdk.ppc.rpm
Mandriva Linux Mandrake 8.0
-
Mandrake 8.0 i386 bind-9.1.1-1.1mdk.i586.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/8.0/RPMS/bind-9.1.1-1.1md k.i586.rpm -
Mandrake 8.0 i386 bind-devel-9.1.1-1.1mdk.i586.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/8.0/RPMS/bind-devel-9.1.1 -1.1mdk.i586.rpm -
Mandrake 8.0 i386 bind-utils-9.1.1-1.1mdk.i586.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/8.0/RPMS/bind-utils-9.1.1 -1.1mdk.i586.rpm
Mandriva Linux Mandrake 8.1 ia64
-
Mandrake 8.1 ia64 bind-9.2.0-0.rc3.2mdk.ia64.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/ia64/8.1/RPMS/bind-9.2.0- 0.rc3.2mdk.ia64.rpm -
Mandrake 8.1 ia64 bind-devel-9.2.0-0.rc3.2mdk.ia64.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/ia64/8.1/RPMS/bind-devel- 9.2.0-0.rc3.2mdk.ia64.rpm -
Mandrake 8.1 ia64 bind-utils-9.2.0-0.rc3.2mdk.ia64.rpm
ftp://fr2.rpmfind.net/linux/Mandrake/updates/ia64/8.1/RPMS/bind-utils- 9.2.0-0.rc3.2mdk.ia64.rpm
References
Mandrake Bind 9 Package Insecure File Permissions Vulnerability
References:
References: