CERT-In Vulnerability Note
CIVN-2014-0285
Multiple Vulnerabilities in ISC BIND GeoIP feature
Original Issue Date:December 16, 2014
Severity Rating: HIGH
Systems Affected
- ISC BIND 9.10.0
- ISC BIND 9.10.1
Overview
Multiple vulnerabilitieshave been reported in the GeoIP feature of the ISC BIND, which could be exploited by a remote attacker to cause denial of service (DoS) condition or improper loading of GeoIP databases.
Description
The vulnerabilities exist in ISC BINDGeoIP functionality that triggers multiple assertion failure errors via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options. A remote attacker could exploit this issue by sending specially crafted DNS queries to trigger assertion failure errors resulting indenial of service (DoS) conditions.
Another vulnerability is also reported in the GeoIP feature of ISC BIND that may cause the GeoIP databases to be improperly loaded, if their location was changed while BIND was running.
Workaround
- Ensure both IPv6 and IPv4GeoIP databases are loaded.
- Disable IPv6 support
Solution
Upgrade to BIND 9.10.1-P1
http://www.isc.org/downloads
Vendor Information
ISC BIND
https://kb.isc.org/article/AA-01217/
References
IBM ISS
http://xforce.iss.net/xforce/xfdb/99188
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36694
AusCERT
http://www.auscert.org.au/render.html?it=21368
RedHat
https://access.redhat.com/security/cve/CVE-2014-8680
CVE Name
CVE-2014-8680
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|