Buffer overflow and DoS i BIND

From: Jørgensen, Bjørn Anders (jorgensen@NETTSPESIALISTEN.NO)
Date: 07/03/02


Date:         Wed, 3 Jul 2002 10:15:19 +0200
From: "Jørgensen, Bjørn Anders" <jorgensen@NETTSPESIALISTEN.NO>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

For those running BIND on Windows:

http://www.cert.org/advisories/CA-2002-19.html

---------------------------------------------------------------
All versions of BIND 4 from 4.8.1 prior to BIND 4.9.9 are vulnerable.
All versions of BIND 8 prior to BIND 8.2.6 are vulnerable.
All versions of BIND 8.3.x prior to BIND 8.3.3 are vulnerable.
BIND versions BIND 9.2.0 and BIND 9.2.1 are vulnerable.
The status of BIND 4.8 is unknown, assume that it is vulnerable.
BIND versions BIND 9.0.x and BIND 9.1.x are not vulnerable.
------------------------------------------------------------------

(BTW: Sendmail is also affected)

Funny thing: There's also found a DoS bug in BIND 9 earlier.

http://www.cert.org/advisories/CA-2002-14.html

Make sure to patch up vulnerable systems.

- Anders



Relevant Pages

  • Re: Bind 9.2.X exploit???
    ... All versions of the stub resolver library from BIND 8 prior to 8.2.6. ... > if anyone wanna test it I can send the source code. ... > For more information on this free incident handling, management ...
    (Incidents)
  • Problem with named/bind 9.3.1 (FC4)(exiting (due to assertion failure))
    ... After receiving this error message on my logfile I found on google that this was a problem with bind versions prior to 9.2.1. ...
    (Fedora)
  • Re: postback resetting checkbox state
    ... Don't rebind the data in Page_Load every time. ... Page.IsPostBack Then and only bind then. ... The viewstate is reconstituted ... prior to Page_Load, so you will overwrite every time if you bind there. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Address already in use when using socket
    ... Bearish wrote: ... this prior to attempting to bind to the port. ...
    (comp.lang.python)
  • Re: AD and Expired Password Checking and how to test?
    ... Directory: Windows 2000 ... Using server: ctstepdown.whatever.com:389 ... So then, now I'm still puzzled why, when I set the system clock to 10/11/06, I get "Invalid credential" when I try to do a bind, using either a simple bind or SSPI bind. ... adfind -sc u:username pwdlastset -tdcs ...
    (microsoft.public.windows.server.active_directory)