ISC BIND Cache Update Policy Can Be Bypassed to Allow Revoked Domain Names to Remain Resolvable
|
|
SecurityTracker Alert ID: 1026647 |
|
SecurityTracker URL: http://securitytracker.com/id/1026647
|
|
CVE Reference:
CVE-2012-1033
(Links to External Site)
|
Date: Feb 8 2012
|
Impact:
Modification of system information
|
Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 9.x
|
Description:
A vulnerability was reported in BIND. A remote user can cause revoked domain names to remain resolvable.
A remote user can exploit a flaw in the DNS cache update policy to cause a revoked domain name to remain as resolvable after the domain name has been deleted from the domain registry and after the associated TTL has expired.
The original advisory was presented at NDSS 2012 ("Ghost Domain Names: Revoked Yet Still Resolvable").
Jian Jiang, Jinjin Liang, Kang Li, Jun Li, Haixin Duan, and Jianping Wu reported this vulnerability.
|
Impact:
A remote user can cause revoked domain names to remain resolvable.
|
Solution:
No solution was available at the time of this entry.
The vendor is working on a patch.
The vendor's advisory is available at:
https://www.isc.org/software/bind/advisories/cve-2012-1033
|
Vendor URL: www.isc.org/software/bind/advisories/cve-2012-1033 (Links to External Site)
|
Cause:
State error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 08 Feb 2012 20:24:21 +0000
Subject: ISC BIND
|
https://www.isc.org/software/bind/advisories/cve-2012-1033
CVE-2012-1033
|
|