ISC BIND 9 DNS RDATA Handling CVE-2012-5166 Remote Denial of Service Vulnerability
BID:55852
Info
ISC BIND 9 DNS RDATA Handling CVE-2012-5166 Remote Denial of Service Vulnerability
| Bugtraq ID: | 55852 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-5166 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2012 12:00AM |
| Updated: | Jul 29 2016 05:00PM |
| Credit: | Jake Montgomery of Dyn, Inc. |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.C5.11 Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP1 LTSS SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE Suse Linux Enterprise Desktop 11 SP2 SuSE Suse Linux Enterprise Desktop 10 SP4 SuSE Linux Enterprise Software Development Kit 11 SP2 Sun Solaris 9 Sun Solaris 11 Sun Solaris 10 Slackware Linux x86_64 -current Slackware Linux 14.0 x86_64 Slackware Linux 14.0 Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux -current Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux 5 Server Oracle VM Server for x86 3.4 Oracle VM Server for x86 3.3 Oracle VM Server for x86 3.2 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 McAfee FireWall Enterprise 8.2.1 McAfee FireWall Enterprise 7.0.1.03H04 McAfee FireWall Enterprise 7.0.1.03 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 ISC BIND 9.6 ISC BIND 9.4 ISC BIND 9.2 ISC BIND 9.7.1 ISC BIND 9.7.0 Intel McAfee Firewall Enterprise 8.3 Intel McAfee Firewall Enterprise 7.0.1.02 IBM AIX 7.1.2 IBM AIX 7.1.1 IBM AIX 7.1 6 IBM AIX 7.1 IBM AIX 6.1.8 IBM AIX 6.1.7 5 IBM AIX 6.1.7 IBM AIX 6.1.6 8 IBM AIX 6.1.6 IBM AIX 6.1.5 IBM AIX 6.1.4 IBM AIX 6.1.3 IBM AIX 6.1.2 IBM AIX 6.1.1 IBM AIX 5.3.12 6 IBM AIX 5.3.12 IBM AIX 5.3.10 IBM AIX 5.3.9 IBM AIX 5.3.8 IBM AIX 5.3.7 IBM AIX 5.3 L IBM AIX 7.1.1.5 IBM AIX 7.1 IBM AIX 6.1 IBM AIX 5.3.12 IBM AIX 5.3.11 IBM AIX 5.3 HP TCP/IP Services for OpenVMS BIND 5.7 ECO5 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux FreeBSD FreeBSD 9.1 FreeBSD FreeBSD 9.0-RC3 FreeBSD FreeBSD 9.0-RC1 FreeBSD FreeBSD 9.0 FreeBSD FreeBSD 8.3 FreeBSD FreeBSD 8.2 FreeBSD FreeBSD 8.1 FreeBSD FreeBSD 8.0-RELEASE FreeBSD FreeBSD 7.4 FreeBSD FreeBSD 7.3 FreeBSD FreeBSD 7.2 FreeBSD FreeBSD 7.1 F5 Enterprise Manager 3.0 F5 Enterprise Manager 2.3 F5 Enterprise Manager 2.0 F5 Enterprise Manager 1.8 F5 Enterprise Manager 1.6 F5 BIG-IP PSM 11.2 F5 BIG-IP PSM 11.1 F5 BIG-IP PSM 11.0 F5 BIG-IP PSM 10.2.4 F5 BIG-IP PSM 10.0 F5 BIG-IP PSM 9.4.8 F5 BIG-IP PSM 9.4.5 F5 BIG-IP PSM 11.2.1 HF1 F5 BIG-IP PSM 11.2.1 F5 BIG-IP PSM 11.2.0 HF2 F5 BIG-IP PSM 10.2.4 HF4 F5 BIG-IP LTM 11.2 F5 BIG-IP LTM 11.0 F5 BIG-IP LTM 10.2.4 F5 BIG-IP LTM 10.0 F5 BIG-IP LTM 9.6.1 F5 BIG-IP LTM 9.4.8 F5 BIG-IP LTM 9.0 F5 BIG-IP LTM 11.2.1 HF1 F5 BIG-IP LTM 11.2.1 F5 BIG-IP LTM 11.2.0 HF2 F5 BIG-IP LTM 11.1.0 F5 BIG-IP LTM 10.2.4 HF4 F5 BIG-IP Link Controller 9.4.8 0 F5 BIG-IP Link Controller 11.2.0 0 F5 BIG-IP Link Controller 10.0.0 0 F5 BIG-IP Link Controller 11.2.1 F5 BIG-IP Link Controller 11.1 F5 BIG-IP Link Controller 11.0 F5 BIG-IP Link Controller 10.2.4 F5 BIG-IP Link Controller 9.2.2 F5 BIG-IP Link Controller 11.2.1 HF1 F5 BIG-IP Link Controller 11.2.0 HF2 F5 BIG-IP Link Controller 10.2.4 HF4 F5 BIG-IP GTM 11.2 F5 BIG-IP GTM 11.0 F5 BIG-IP GTM 10.2.4 F5 BIG-IP GTM 10.0 F5 BIG-IP GTM 9.4.8 F5 BIG-IP GTM 9.2.2 F5 BIG-IP GTM 11.2.1 HF1 F5 BIG-IP GTM 11.2.1 F5 BIG-IP GTM 11.2.0 HF2 F5 BIG-IP GTM 11.1.0 F5 BIG-IP GTM 10.2.4 HF4 F5 BIG-IP Edge Gateway 11.2.1 F5 BIG-IP Edge Gateway 11.2 F5 BIG-IP Edge Gateway 11.1 F5 BIG-IP Edge Gateway 11.0 F5 BIG-IP Edge Gateway 10.2.4 F5 BIG-IP Edge Gateway 10.2.4 HF4 F5 BIG-IP Edge Gateway 10.1 F5 BIG-IP ASM 9.4.8 0 F5 BIG-IP ASM 11.2.0 HF2 0 F5 BIG-IP ASM 11.2.0 0 F5 BIG-IP ASM 11.0.0 0 F5 BIG-IP ASM 10.2.4 0 F5 BIG-IP ASM 10.0.0 0 F5 BIG-IP ASM 9.2 F5 BIG-IP ASM 11.2.1 HF1 F5 BIG-IP ASM 11.2.1 F5 BIG-IP ASM 11.1.0 F5 BIG-IP ASM 10.2.4 HF4 F5 BIG-IP APM 11.2 F5 BIG-IP APM 11.0 F5 BIG-IP APM 10.2.4 F5 BIG-IP APM 11.2.1 HF1 F5 BIG-IP APM 11.2.1 F5 BIG-IP APM 11.2.0 HF2 F5 BIG-IP APM 11.1.0 F5 BIG-IP APM 10.2.4 HF4 F5 BIG-IP APM 10.1 EMC VPLEX GeoSynchrony 5.2.1 EMC VPLEX GeoSynchrony 5.2 SP1 EMC VPLEX GeoSynchrony 4.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Collax Collax Business Server 5.5.2 Collax Collax Business Server 5.5 CentOS CentOS 5 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.5 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.0.1 Avaya Aura Session Manager 6.3 Avaya Aura Session Manager 6.2.3 Avaya Aura Session Manager 6.2.2 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2.1 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1.1 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Apple Mac OS X Server 10.7.5 Apple Mac OS X 10.8.4 Apple Mac OS X 10.8.2 Apple Mac OS X 10.8.1 Apple Mac OS X 10.7.5 Apple Mac OS X 10.8.3 Apple Mac OS X 10.8 |
| Not Vulnerable: |
Intel McAfee Firewall Enterprise 8.3.0P02 Intel McAfee Firewall Enterprise 8.2.1P06 Intel McAfee Firewall Enterprise 7.0.1.03H06 FreeBSD FreeBSD 9.1-RC2 F5 Enterprise Manager 3.1 F5 BIG-IP PSM 11.3 F5 BIG-IP PSM 11.2.1 HF2 F5 BIG-IP PSM 11.2.0 HF3 F5 BIG-IP PSM 10.2.4 HF5 F5 BIG-IP LTM 11.2 HF3 F5 BIG-IP LTM 11.3.0 F5 BIG-IP LTM 11.2.1 HF2 F5 BIG-IP LTM 10.2.4 HF5 F5 BIG-IP Link Controller 11.3 F5 BIG-IP Link Controller 11.2 HF3 F5 BIG-IP Link Controller 11.2.1 HF2 F5 BIG-IP Link Controller 10.2.4 HF5 F5 BIG-IP GTM 11.3 F5 BIG-IP GTM 11.2.1 HF2 F5 BIG-IP GTM 11.2.0 HF3 F5 BIG-IP GTM 10.2.4 HF5 F5 BIG-IP Edge Gateway 11.3 F5 BIG-IP Edge Gateway 11.2 HF3 F5 BIG-IP Edge Gateway 11.2.1 HF2 F5 BIG-IP Edge Gateway 10.2.4 HF5 F5 BIG-IP ASM 11.3.0 F5 BIG-IP ASM 11.2.1 HF2 F5 BIG-IP ASM 11.2.0 HF3 F5 BIG-IP ASM 10.2.4 HF5 F5 BIG-IP APM 11.3.0 F5 BIG-IP APM 11.2.0 HF3 F5 BIG-IP APM 10.2.4 HF5 F5 BIG-IP Analytics 11.3 F5 BIG-IP Analytics 11.2.1 HF2 EMC VPLEX GeoSynchrony 5.3 Collax Collax Business Server 5.5.4 Avaya Aura Session Manager 6.3.1 Apple Mac OS X 10.8.5 |
Discussion
ISC BIND 9 DNS RDATA Handling CVE-2012-5166 Remote Denial of Service Vulnerability
ISC BIND is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the 'named' process to lockup, denying service to legitimate users.
ISC BIND is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the 'named' process to lockup, denying service to legitimate users.
Exploit / POC
ISC BIND 9 DNS RDATA Handling CVE-2012-5166 Remote Denial of Service Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
ISC BIND 9 DNS RDATA Handling CVE-2012-5166 Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
Slackware Linux 13.1
Slackware Linux x86_64 -current
Slackware Linux 14.0 x86_64
MandrakeSoft Enterprise Server 5
Apple Mac OS X 10.8.4
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
-
Slackware bind-9.7.6_P4-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ bind-9.7.6_P4-i486-1_slack12.2.tgz
Slackware Linux 13.1
-
Slackware bind-9.7.6_P4-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ bind-9.7.6_P4-i486-1_slack13.1.txz
Slackware Linux x86_64 -current
-
Slackware bind-9.9.2-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ n/bind-9.9.2-x86_64-1.txz
Slackware Linux 14.0 x86_64
-
Slackware bind-9.9.1_P4-x86_64-1_slack14.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/package s/bind-9.9.1_P4-x86_64-1_slack14.0.txz
MandrakeSoft Enterprise Server 5
-
Mandriva bind-9.7.6-0.0.P4.0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva bind-devel-9.7.6-0.0.P4.0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva bind-doc-9.7.6-0.0.P4.0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva bind-utils-9.7.6-0.0.P4.0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Apple Mac OS X 10.8.4
-
Apple OSXUpd10.8.5.dmg
http://www.apple.com/support/downloads/
References
ISC BIND 9 DNS RDATA Handling CVE-2012-5166 Remote Denial of Service Vulnerability
References:
References:
- Collax Business Server Homepage (collax)
- CVE-2012-5166 Denial of Service vulnerability in ISC BIND (Oracle)
- ESA-2014-016: EMC VPLEX Multiple Vulnerabilities (EMC)
- ISC BIND Homepage (ISC)
- Xerox Security Bulletin XRX13-003 (Xerox)
- Xerox Security Bulletin XRX13-004 (Xerox)
- About the security content of OS X Mountain Lion v10.8.5 and Security Update 201 (Apple)
- bind security update (RHSA-2012-1363) (Avaya Inc)
- CVE-2012-5166: Specially crafted DNS data can cause a lockup in named (ISC)
- Firewall Enterprise response to CVE-2012-5166 (Intel)
- FreeBSD-SA-12:06.bind Remote Denial of Service Vulnerability (FreeBSD)
- HPSBOV03540 rev.1 - HPE OpenVMS TCPIP Bind Services and OpenVMS TCPIP IPC Servic (HP)
- HPSBUX02823 SSRT100976 rev.1 - HP-UX Running BIND, Remote Denial of Service (DoS (HP)
- sol14201: BIND denial-of-service attack CVE-2012-5166 / CVE-2012-4244 (F5 Networks)
- Vulnerability in AIX bind (IBM)