copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2000.340 -- RHSA-2000:107-01 -- Updated bind packages fixing DoS attack available

Date: 14 November 2000
References: ESB-2000.343  ESB-2000.377  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----

===========================================================================
              AUSCERT External Security Bulletin Redistribution
                             
                      ESB-2000.340 -- RHSA-2000:107-01
              Updated bind packages fixing DoS attack available
                              14 November 2000

===========================================================================

	AusCERT Security Bulletin Summary
	---------------------------------

Product:                bind
Vendor:                 Internet Software Consortium
Operating System:       Red Hat Linux
			Linux
			Unix
Impact:                 Denial of Service
Access Required:        Remote

- --------------------------BEGIN INCLUDED TEXT--------------------

- ---------------------------------------------------------------------
                   Red Hat, Inc. Security Advisory

Synopsis:          Updated bind packages fixing DoS attack available
Advisory ID:       RHSA-2000:107-01
Issue date:        2000-11-11
Updated on:        2000-11-11
Product:           Red Hat Linux
Keywords:          bind DoS denial of service attack exploit security
Cross references:  N/A
- ---------------------------------------------------------------------

1. Topic:

A remote DoS (denial of service) attack is possible with bind versions
prior to 8.2.2_P7.

2. Relevant releases/architectures:

Red Hat Linux 5.2 - i386, alpha, sparc
Red Hat Linux 6.0 - i386, alpha, sparc
Red Hat Linux 6.1 - i386, alpha, sparc
Red Hat Linux 6.2 - i386, alpha, sparc
Red Hat Linux 6.2EE - i386, alpha, sparc
Red Hat Linux 7.0 - i386, alpha, sparc
Red Hat Linux 7.0J - i386, alpha, sparc

3. Problem description:

A bug in bind 8.2.2_P5 allows for a denial of service attack.
If named is open to zone transfers and recursive resolving, it will crash
after a ZXFR for the authoritative zone and a query of a remote hostname.

4. Solution:

For each RPM for your particular architecture, run:

rpm -Fvh [filename]

where filename is the name of the RPM.


Disabling zone transfers to non-trusted hosts by adding
allow-transfer { trusted-hosts; };
to /etc/named.conf prevents the exploit from working on older releases,
however, this does not fix the problem.

5. Bug IDs fixed (http://bugzilla.redhat.com/bugzilla for more info):

20546 - bind 8.2.2-P5 remote DoS


6. RPMs required:

Red Hat Linux 5.2:

alpha:
ftp://updates.redhat.com/5.2/alpha/bind-8.2.2_P7-0.5.2.alpha.rpm

sparc:
ftp://updates.redhat.com/5.2/sparc/bind-8.2.2_P7-0.5.2.sparc.rpm

i386:
ftp://updates.redhat.com/5.2/i386/bind-8.2.2_P7-0.5.2.i386.rpm

sources:
ftp://updates.redhat.com/5.2/SRPMS/bind-8.2.2_P7-0.5.2.src.rpm

Red Hat Linux 6.0:

sparc:
ftp://updates.redhat.com/6.0/sparc/bind-8.2.2_P7-0.6.2.sparc.rpm

i386:
ftp://updates.redhat.com/6.0/i386/bind-8.2.2_P7-0.6.2.i386.rpm

alpha:
ftp://updates.redhat.com/6.0/alpha/bind-8.2.2_P7-0.6.2.alpha.rpm

sources:
ftp://updates.redhat.com/6.0/SRPMS/bind-8.2.2_P7-0.6.2.src.rpm

Red Hat Linux 6.1:

sparc:
ftp://updates.redhat.com/6.1/sparc/bind-8.2.2_P7-0.6.2.sparc.rpm

i386:
ftp://updates.redhat.com/6.1/i386/bind-8.2.2_P7-0.6.2.i386.rpm

alpha:
ftp://updates.redhat.com/6.1/alpha/bind-8.2.2_P7-0.6.2.alpha.rpm

sources:
ftp://updates.redhat.com/6.1/SRPMS/bind-8.2.2_P7-0.6.2.src.rpm

Red Hat Linux 6.2:

alpha:
ftp://updates.redhat.com/6.2/alpha/bind-8.2.2_P7-0.6.2.alpha.rpm

sparc:
ftp://updates.redhat.com/6.2/sparc/bind-8.2.2_P7-0.6.2.sparc.rpm

i386:
ftp://updates.redhat.com/6.2/i386/bind-8.2.2_P7-0.6.2.i386.rpm

sources:
ftp://updates.redhat.com/6.2/SRPMS/bind-8.2.2_P7-0.6.2.src.rpm

Red Hat Linux 7.0:

alpha:
ftp://updates.redhat.com/7.0/alpha/bind-8.2.2_P7-1.alpha.rpm

sparc:
ftp://updates.redhat.com/7.0/sparc/bind-8.2.2_P7-1.sparc.rpm

i386:
ftp://updates.redhat.com/7.0/i386/bind-8.2.2_P7-1.i386.rpm

sources:
ftp://updates.redhat.com/7.0/SRPMS/bind-8.2.2_P7-1.src.rpm

7. Verification:

MD5 sum                           Package Name
- --------------------------------------------------------------------------
a8384e027a701ac18c222e8cf692d1bb  5.2/SRPMS/bind-8.2.2_P7-0.5.2.src.rpm
1a9d82ed254a4316000b0951870b7a1a  5.2/alpha/bind-8.2.2_P7-0.5.2.alpha.rpm
6fdd9dc50a075d82b457f6a1079cdef6  5.2/i386/bind-8.2.2_P7-0.5.2.i386.rpm
92801fa17e15665fab7ea18b9623ecd7  5.2/sparc/bind-8.2.2_P7-0.5.2.sparc.rpm
c663e471d722b6d59d147233c96466f9  6.0/SRPMS/bind-8.2.2_P7-0.6.2.src.rpm
95c9a4aa98c5278195df5853ea0f8371  6.0/alpha/bind-8.2.2_P7-0.6.2.alpha.rpm
a6dc64455c83374894d1ac149d27f9ba  6.0/i386/bind-8.2.2_P7-0.6.2.i386.rpm
29baa5949e4f67089e434148a4d1bf8c  6.0/sparc/bind-8.2.2_P7-0.6.2.sparc.rpm
c663e471d722b6d59d147233c96466f9  6.1/SRPMS/bind-8.2.2_P7-0.6.2.src.rpm
95c9a4aa98c5278195df5853ea0f8371  6.1/alpha/bind-8.2.2_P7-0.6.2.alpha.rpm
a6dc64455c83374894d1ac149d27f9ba  6.1/i386/bind-8.2.2_P7-0.6.2.i386.rpm
29baa5949e4f67089e434148a4d1bf8c  6.1/sparc/bind-8.2.2_P7-0.6.2.sparc.rpm
c663e471d722b6d59d147233c96466f9  6.2/SRPMS/bind-8.2.2_P7-0.6.2.src.rpm
95c9a4aa98c5278195df5853ea0f8371  6.2/alpha/bind-8.2.2_P7-0.6.2.alpha.rpm
a6dc64455c83374894d1ac149d27f9ba  6.2/i386/bind-8.2.2_P7-0.6.2.i386.rpm
29baa5949e4f67089e434148a4d1bf8c  6.2/sparc/bind-8.2.2_P7-0.6.2.sparc.rpm
9db3ab376d44984cf200a486c15fb267  7.0/SRPMS/bind-8.2.2_P7-1.src.rpm
cdaad5917739f5c20e4d01a37750386d  7.0/alpha/bind-8.2.2_P7-1.alpha.rpm
3ca7a0db5c91992478737bf7564ad148  7.0/i386/bind-8.2.2_P7-1.i386.rpm
105382156bffc1543e3907b12c2a417c  7.0/sparc/bind-8.2.2_P7-1.sparc.rpm

These packages are GPG signed by Red Hat, Inc. for security.  Our key
is available at:
    http://www.redhat.com/corp/contact.html

You can verify each package with the following command:
    rpm --checksig  <filename>

If you only wish to verify that each package has not been corrupted or
tampered with, examine only the md5sum with the following command:
    rpm --checksig --nogpg <filename>

8. References:

http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=20546


Copyright(c) 2000 Red Hat, Inc.

- --------------------------END INCLUDED TEXT--------------------

This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content.  The decision to use any or all of this information is
the responsibility of each user or organisation, and should be done so in
accordance with site policies and procedures.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the original authors to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

	http://www.auscert.org.au/Information/advisories.html

If you believe that your system has been compromised, contact AusCERT or
your representative in FIRST (Forum of Incident Response and Security
Teams).

Internet Email: auscert@auscert.org.au
Facsimile:	(07) 3365 7031
Telephone:	(07) 3365 4417 (International: +61 7 3365 4417)
		AusCERT personnel answer during Queensland business hours
		which are GMT+10:00 (AEST).
		On call after hours for emergencies.


-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
Comment: ftp://ftp.auscert.org.au/pub/auscert/AUSCERT_PGP.key

iQCVAwUBOlSNOCh9+71yA2DNAQFm2gP+MI+abClxC/ihci3wKmnnWZqci4VQL/5U
2Ayboy+0esyvKYiT6Vcwv+HcfePGs4Zg3Qx+RPIU/gLp3vE7Q1rKc1ESgCvoO74u
e8exzUdUvaL1dUiPwWdsHbVup3J15JT54UH66kyH2YkA4J6iVa8akNCB6KYUEQ/J
BEJ7buIj4tE=
=B1hG
-----END PGP SIGNATURE-----