Search:     Advanced search
server monitoring

ISC BIND 9 Multiple Remote DoS

Article ID: 22311
Last updated: 27 Jan, 2009
Views: 386
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

ISC BIND 9 Multiple Remote DoS

This script is Copyright (C) 2006-2009 Tenable Network Security, Inc.

FamilyDNS
Plugin ID22311
Bugtraq ID19859
CVE IDCVE-2006-4095
CVE-2006-4096

Description:

Synopsis :

The remote name server may be affected by multiple denial of service
vulnerabilities.

Description :

The version of BIND installed on the remote host suggests that it
suffers from multiple denial of service vulnerabilities, which may be
triggered by either by sending a large volume of recursive queries or
queries for SIG records where there are multiple SIG(covered) RRsets.

Note that obtained the version by sending a special DNS request
for the text version.bind in the domain chaos, the value of which
can be and sometimes is tweaked by DNS administrators.

See also :

http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=en
http://www.isc.org/index.pl?/sw/bind/bind-security.php

Solution :

Upgrade to BIND 9.4.0b2 / 9.3.3rc2 / 9.3.2-P1 / 9.2.7rc2 / 9.2.6-P1 or
later.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
This article was:   Helpful | Not Helpful
Prev   Next
DNS Cache Snooping     ISC BIND query.c query_addsoa Function Unspecified Recursive...