CERT-In Vulnerability Note
CIVN-2007-0142
Remote Code Execution Vulnerability in Microsoft DNS Server
Original Issue Date:November 14, 2007
Severity Rating: MEDIUM
Systems Affected
- Microsoft Windows 2000 Server Service Pack 4
- Microsoft Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows Server 2003 x64 Edition
- Microsoft Windows Server 2003 x64 Edition Service Pack 2
- Microsoft Windows Server 2003 SP1 Itanium
- Microsoft Windows Server 2003 SP2 Itanium
Overview
A vulnerability have been reported in Microsoft DNS server that could be exploited by an attacker to poison the DNS Server cache .The vulnerability could allow unauthenticated attacker to cause a window DNS server to provide incorrect response to DNS queries.
Description
A spoofing vulnerability exists in Microsoft DNS server service dns.exe while sending out queries to upstream DNS server ..
This vulnerability could allow an attacker to poison the DNS cache via a specially crafted DNS response with a guessed transaction value. An attacker who successfully exploited this vulnerability could respond to a DNS query with false or misleading information, thereby redirecting network traffic from legitimate location. This vulnerability applies to DNS server that performs recursive lookups
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS07-062
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS07-062.mspx
References
FrSIRT
http://www.frsirt.com/english/advisories/2007/3848
Secunia
http://secunia.com/advisories/27584/
SecurityFocus
http://www.securityfocus.com/bid/25919/discuss
Xforce
http://xforce.iss.net/xforce/xfdb/36805
US-CERT
http://www.kb.cert.org/vuls/id/484649
CVE Name
CVE-2007-3898
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|