Multiple Vendor BIND (NXT Overflow & Denial of Service) Vulnerabilities

BID:788

Info

Multiple Vendor BIND (NXT Overflow & Denial of Service) Vulnerabilities

Bugtraq ID: 788
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Nov 10 1999 12:00AM
Updated: Nov 10 1999 12:00AM
Credit: This was published in the ISC advisory regarding this available at: http://www.isc.org/products/BIND/bind-security-19991108.html
Vulnerable: Sun Solaris 7.0_x86
Sun Solaris 7.0
SGI IRIX 6.5.17
SGI IRIX 6.5.16
SGI IRIX 6.5.15
SGI IRIX 6.5.14
SGI IRIX 6.5.13
SGI IRIX 6.5.12
SGI IRIX 6.5.11
SGI IRIX 6.5.10
SGI IRIX 6.5.9
SGI IRIX 6.5.8
SGI IRIX 6.5.7
SGI IRIX 6.5.6
SGI IRIX 6.5.5
SGI IRIX 6.5.4
SGI IRIX 6.5.3
SGI IRIX 6.5.2
SGI IRIX 6.5.1
SGI IRIX 6.5
ISC BIND 8.2.2 p1
ISC BIND 8.2.2
ISC BIND 8.2.1
ISC BIND 8.2
- Caldera OpenLinux 2.2
- Caldera OpenLinux 1.3
- Caldera UnixWare 7.1.1
- IBM AIX 4.3.3
- IBM AIX 4.3.2
- IBM AIX 4.3.1
- IBM AIX 4.3
- Redhat Linux 6.1 i386
- Redhat Linux 6.0
- Redhat Linux 5.2 i386
- Redhat Linux 5.1
- Redhat Linux 5.0
- Redhat Linux 4.2
- Redhat Linux 4.1
- Redhat Linux 4.0
- Slackware Linux 4.0
ISC BIND 8.1.2
+ HP HP-UX 11.11
+ HP HP-UX 11.0
ISC BIND 8.1.1
ISC BIND 8.1
ISC BIND 4.9.7
+ HP HP-UX 11.0 4
+ HP HP-UX 11.0
+ HP HP-UX 10.24
+ HP HP-UX 10.20
+ HP HP-UX 10.10
ISC BIND 4.9.6
ISC BIND 4.9.5 P1
ISC BIND 4.9.5
Not Vulnerable: Sun Solaris 8_x86
Sun Solaris 8_sparc
SGI IRIX 6.5.18
ISC BIND 8.2.2 p2

Discussion

Multiple Vendor BIND (NXT Overflow & Denial of Service) Vulnerabilities

There are several vulnerabilities in recent BIND packages (pre 8.2.2).

The first is a buffer overflow condition which is a result of BIND improperly validating NXT records. The consequence of this being exploited is a remote root compromise (assuming that BIND is running as root, which is default).

The second is a denial of service which can occur if BIND does not validate SIG records properly.

The next is a bug which allows attackers to cause BIND to consume more file descriptors than can be managed, causing named to crash.

The fourth vulnerability is another denial of service which can be caused locally if certain permission conditions are met when validating zone information loaded from disk files.

The last is a vulnerability which has to do with closing TCP sockets. If protocols for doing so are not adhered to, BIND can be paused for 120 seconds at a time.

Exploit / POC

Multiple Vendor BIND (NXT Overflow & Denial of Service) Vulnerabilities

CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

ADM Crew has released an exploit:

Solution / Fix

Multiple Vendor BIND (NXT Overflow & Denial of Service) Vulnerabilities

Solution:
ISC Recommends updating to BIND 8.2.2. Patchlevel 5.

The following vendor patches are available as of May 25, 2000:

Hewlett-Packard HP-UX patches:
s700_800 HP-UX release 10.01, 10.10 & 10.20 BIND 4.9.7 PHNE_20618
s700_800 HP-UX release 10.24 (VVOS) BIND 4.9.7 PHNE_21288
s700_800 HP-UX release 11.00 BIND 4.9.7 PHNE_20619
s700_800 HP-UX release 11.04 (VVOS) BIND 4.9.7 PHNE_21090

The bind revision 8.1.2 upgrade is available for HP-UX 11.00 via a web page:
http://www.software.hp.com/products/DNS_BIND/index.html

Caldera

ftp://ftp.calderasystems.com/pub/OpenLinux/updates/2.3/current

MD5s

db1dda05dbe0f67c2bd2e5049096b42c RPMS/bind-8.2.2p3-1.i386.rpm

82bbe025ac091831904c71c885071db1 RPMS/bind-doc-8.2.2p3-1.i386.rpm

2f9a30444046af551eafd8e6238a50c6 RPMS/bind-utils-8.2.2p3-1.i386.rpm

0e4f041549bdd798cb505c82a8911198 SRPMS/bind-8.2.2p3-1.src.rpm

Red Hat Linux 4.x:

Intel:
ftp://updates.redhat.com/4.2/i386/bind-8.2.2_P3-0.4.2.i386.rpm
ftp://updates.redhat.com/4.2/i386/bind-devel-8.2.2_P3-0.4.2.i386.rpm
ftp://updates.redhat.com/4.2/i386/bind-utils-8.2.2_P3-0.4.2.i386.rpm

Alpha:
ftp://updates.redhat.com/4.2/alpha/bind-8.2.2_P3-0.4.2.alpha.rpm
ftp://updates.redhat.com/4.2/alpha/bind-devel-8.2.2_P3-0.4.2.alpha.rpm
ftp://updates.redhat.com/4.2/alpha/bind-utils-8.2.2_P3-0.4.2.alpha.rpm

Sparc:
ftp://updates.redhat.com/4.2/sparc/bind-8.2.2_P3-0.4.2.sparc.rpm
ftp://updates.redhat.com/4.2/sparc/bind-devel-8.2.2_P3-0.4.2.sparc.rpm
ftp://updates.redhat.com/4.2/sparc/bind-utils-8.2.2_P3-0.4.2.sparc.rpm

Source packages:
ftp://updates.redhat.com/4.2/SRPMS/bind-8.2.2_P3-0.4.2.src.rpm

Red Hat Linux 5.x:

Intel:
ftp://updates.redhat.com/5.2/i386/bind-8.2.2_P3-0.5.2.i386.rpm
ftp://updates.redhat.com/5.2/i386/bind-devel-8.2.2_P3-0.5.2.i386.rpm
ftp://updates.redhat.com/5.2/i386/bind-utils-8.2.2_P3-0.5.2.i386.rpm

Alpha:
ftp://updates.redhat.com/5.2/alpha/bind-8.2.2_P3-0.5.2.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/bind-devel-8.2.2_P3-0.5.2.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/bind-utils-8.2.2_P3-0.5.2.alpha.rpm

Sparc:
ftp://updates.redhat.com/5.2/sparc/bind-8.2.2_P3-0.5.2.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/bind-devel-8.2.2_P3-0.5.2.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/bind-utils-8.2.2_P3-0.5.2.sparc.rpm

Source packages:
ftp://updates.redhat.com/5.2/SRPMS/bind-8.2.2_P3-0.5.2.src.rpm

Red Hat Linux 6.x:

Intel:
ftp://updates.redhat.com/6.1/i386/bind-8.2.2_P3-1.i386.rpm
ftp://updates.redhat.com/6.1/i386/bind-devel-8.2.2_P3-1.i386.rpm
ftp://updates.redhat.com/6.1/i386/bind-utils-8.2.2_P3-1.i386.rpm

Alpha:
ftp://updates.redhat.com/6.0/alpha/bind-8.2.2_P3-1.alpha.rpm
ftp://updates.redhat.com/6.0/alpha/bind-devel-8.2.2_P3-1.alpha.rpm
ftp://updates.redhat.com/6.0/alpha/bind-utils-8.2.2_P3-1.alpha.rpm

Sparc:
ftp://updates.redhat.com/6.0/sparc/bind-8.2.2_P3-1.sparc.rpm
ftp://updates.redhat.com/6.0/sparc/bind-devel-8.2.2_P3-1.sparc.rpm
ftp://updates.redhat.com/6.0/sparc/bind-utils-8.2.2_P3-1.sparc.rpm

Source packages:
ftp://updates.redhat.com/6.1/SRPMS/bind-8.2.2_P3-1.src.rpm

Slackware 4.0:

ftp.cdrom.com:/pub/linux/slackware-4.0/patches/bind.tgz

SlackWare 7.0:

ftp.cdrom.com:/pub/linux/slackware-7.0/patches/bind.tgz

IBM AIX:

APAR 4.3.x: IY05851

Patches are available to all Sun customers at http://sunsolve.sun.com

Linux-Mandrake users should use the following upgrades:

md5sum: 185c51a554cd1c2fedf42f002ba8f01f
package: 6.1/RPMS/bind-8.2.2P5-6mdk.i586.rpm

md5sum: 39757dd3b1157685a486fc2c7afe2855
package:6.1/RPMS/bind-devel-8.2.2P5-6mdk.i586.rpm

md5sum: 507e45161ec6f9cbfb17dcf06d0831f0
package:6.1/RPMS/bind-utils-8.2.2P5-6mdk.i586.rpm

md5sum: eeffc6a7d2c7813931a2bbcb8da05a79
source: 6.1/SRPMS/bind-8.2.2P5-6mdk.src.rpm

md5sum: 95ccd87693c8e3c870f1bccd2842489b
package:7.0/RPMS/bind-8.2.2P5-6mdk.i586.rpm

md5sum: 31a1b33c3cf2013ea14ac1d0432a2785
package:7.0/RPMS/bind-devel-8.2.2P5-6mdk.i586.rpm

md5sum: ce92d5be31c4675e5ec21e4a76815633
package:7.0/RPMS/bind-utils-8.2.2P5-6mdk.i586.rpm

md5sum: eeffc6a7d2c7813931a2bbcb8da05a79
source: 7.0/SRPMS/bind-8.2.2P5-6mdk.src.rpm

To upgrade automatically, use « MandrakeUpdate ». If you want to
upgrade manually, download the updated package from one of our FTP
server mirrors and uprade with "rpm -Uvh package_name". All mirrors
are listed on http://www.mandrake.com/en/ftp.php3 Updated packages are
available in the "updates/" directory.

For example, if you are looking for an updated RPM package for
Mandrake 7.0, look for it in: updates/7.0/RPMS/

SGI has reported that IRIX 6.5 shipped with a vulnerable version of BIND 4.9.4p1. This issue will be resolved in IRIX 6.5.18. Additionally, IRIX patch 4725 will resolve this issue for IRIX 6.5.13, 6.5.14, 6.5.15, 6.5.16 and 6.5.17.


Sun Solaris 7.0
  • Sun 106938-03

  • Sun 107018-02


Sun Solaris 7.0_x86
  • Sun 106939-03

  • Sun 107019-02

References

Multiple Vendor BIND (NXT Overflow & Denial of Service) Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report