Vulnerabilities > CVE-2010-3614 - Improper Input Validation vulnerability in ISC Bind

Attack vector
Attack complexity
Privileges required
Confidentiality impact
Integrity impact
Availability impact
low complexity


named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

    a. Service Location Protocol daemon DoS

   This patch fixes a denial-of-service vulnerability in
   the Service Location Protocol daemon (SLPD). Exploitation of this
   vulnerability could cause SLPD to consume significant CPU
   resources.

   VMware would like to thank Nicolas Gregoire and US CERT for
   reporting this issue to us.

   The Common Vulnerabilities and Exposures Project (cve.mitre.org)
   has assigned the name CVE-2010-3609 to this issue.

b. Service Console update for bind

   This patch updates the bind-libs and bind-utils RPMs to version
   9.3.6-4.P1.el5_5.3, which resolves multiple security issues.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the names CVE-2010-3613, CVE-2010-3614, and
   CVE-2010-3762 to these issues.

c. Service Console update for pam

   This patch updates the pam RPM to pam_0.99.6.2-3.27.5437.vmw,
   which resolves multiple security issues with PAM modules.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the names CVE-2010-3316, CVE-2010-3435, and
   CVE-2010-3853 to these issues.

d. Service Console update for rpm, rpm-libs, rpm-python, and popt

   This patch updates rpm, rpm-libs, and rpm-python RPMs to
   4.3.3-22.5437.vmw, and popt to version 1.10.2.3-22.5437.vmw,
   which resolves a security issue.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the name CVE-2010-2059 to this issue.
    Several remote vulnerabilities have been discovered in BIND, an
implementation of the DNS protocol suite. The Common Vulnerabilities
and Exposures project identifies the following problems :

  - CVE-2010-3762
    When DNSSEC validation is enabled, BIND does not
    properly handle certain bad signatures if multiple trust
    anchors exist for a single zone, which allows remote
    attackers to cause a denial of service (server crash)
    via a DNS query.

  - CVE-2010-3614
    BIND does not properly determine the security status of
    an NS RRset during a DNSKEY algorithm rollover, which
    may lead to zone unavailability during rollovers.

  - CVE-2010-3613
    BIND does not properly handle the combination of signed
    negative responses and corresponding RRSIG records in
    the cache, which allows remote attackers to cause a
    denial of service (server crash) via a query for cached
    data.

In addition, this security update improves compatibility with
previously installed versions of the bind9 package. As a result, it is
necessary to initiate the update with 'apt-get dist-upgrade' instead
of 'apt-get update'.
    Updated bind packages that fix two security issues are now available
for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS)
base scores, which give detailed severity ratings, are available for
each vulnerability from the CVE links in the References section.

The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server
(named); a resolver library (routines for applications to use when
interfacing with DNS); and tools for verifying that the DNS server is
operating correctly.

It was discovered that named did not invalidate previously cached
RRSIG records when adding an NCACHE record for the same entry to the
cache. A remote attacker allowed to send recursive DNS queries to
named could use this flaw to crash named. (CVE-2010-3613)

It was discovered that, in certain cases, named did not properly
perform DNSSEC validation of an NS RRset for zones in the middle of a
DNSKEY algorithm rollover. This flaw could cause the validator to
incorrectly determine that the zone is insecure and not protected by
DNSSEC. (CVE-2010-3614)

All BIND users are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues. After installing
the update, the BIND daemon (named) will be restarted automatically.
    The remote host is affected by the vulnerability described in GLSA-201206-01
(BIND: Multiple vulnerabilities)

    Multiple vulnerabilities have been discovered in BIND. Please review the
      CVE identifiers referenced below for details.
  
Impact :

    The vulnerabilities allow remote attackers to cause a Denial of Service
      (daemon crash) via a DNS query, to bypass intended access restrictions,
      to incorrectly cache a ncache entry and a rrsig for the same type and to
      incorrectly mark zone data as insecure.
  
Workaround :

    There is no known workaround at this time.
    It was discovered that named did not invalidate previously cached
RRSIG records when adding an NCACHE record for the same entry to the
cache. A remote attacker allowed to send recursive DNS queries to
named could use this flaw to crash named. (CVE-2010-3613)

A flaw was found in the DNSSEC validation code in named. If named had
multiple trust anchors configured for a zone, a response to a request
for a record in that zone with a bad signature could cause named to
crash. (CVE-2010-3762)

It was discovered that, in certain cases, named did not properly
perform DNSSEC validation of an NS RRset for zones in the middle of a
DNSKEY algorithm rollover. This flaw could cause the validator to
incorrectly determine that the zone is insecure and not protected by
DNSSEC. (CVE-2010-3614)

After installing the update, the BIND daemon (named) will be restarted
automatically.
    last seen2020-06-01
    last seen2020-06-01
    last seen2020-06-01
    New bind packages are available for Slackware 8.1, 9.0, 9.1, 10.0,
10.1, 10.2, 11.0, 12.0, 12.1, 12.2, 13.0, 13.1, and -current to fix
security issues that could allow attackers to successfully query
private DNS records, or cause a denial of service.
    descriptionAdding certain types of signed negative responses to cache doesn
    Updated bind packages that fix three security issues are now available
for Red Hat Enterprise Linux 5.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS)
base scores, which give detailed severity ratings, are available for
each vulnerability from the CVE links in the References section.

The Berkeley Internet Name Domain (BIND) is an implementation of the
Domain Name System (DNS) protocols. BIND includes a DNS server
(named); a resolver library (routines for applications to use when
interfacing with DNS); and tools for verifying that the DNS server is
operating correctly.

It was discovered that named did not invalidate previously cached
RRSIG records when adding an NCACHE record for the same entry to the
cache. A remote attacker allowed to send recursive DNS queries to
named could use this flaw to crash named. (CVE-2010-3613)

A flaw was found in the DNSSEC validation code in named. If named had
multiple trust anchors configured for a zone, a response to a request
for a record in that zone with a bad signature could cause named to
crash. (CVE-2010-3762)

It was discovered that, in certain cases, named did not properly
perform DNSSEC validation of an NS RRset for zones in the middle of a
DNSKEY algorithm rollover. This flaw could cause the validator to
incorrectly determine that the zone is insecure and not protected by
DNSSEC. (CVE-2010-3614)

All BIND users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing
the update, the BIND daemon (named) will be restarted automatically.
    descriptionUpdated bind packages that fix three security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. It was discovered that named did not invalidate previously cached RRSIG records when adding an NCACHE record for the same entry to the cache. A remote attacker allowed to send recursive DNS queries to named could use this flaw to crash named. (CVE-2010-3613) A flaw was found in the DNSSEC validation code in named. If named had multiple trust anchors configured for a zone, a response to a request for a record in that zone with a bad signature could cause named to crash. (CVE-2010-3762) It was discovered that, in certain cases, named did not properly perform DNSSEC validation of an NS RRset for zones in the middle of a DNSKEY algorithm rollover. This flaw could cause the validator to incorrectly determine that the zone is insecure and not protected by DNSSEC. (CVE-2010-3614) All BIND users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-06-01
    descriptionAdding certain types of signed negative responses to cache doesn
    Update to 9.7.2-P3 release which contains various security fixes.
This update also provides bind-dyndb-ldap and dnsperf packages rebuild
against updated bind.
    The security status of an NS RRset is not properly determined during
a DNSKEY algorithm rollover which can allow a remote attacker to cause
a denial of service. Signed negative responses and corresponding RRSIG
records in the cache are not properly handled which can allow a remote
attacker to cause a denial of service.
    last seen2020-06-01
    descriptionAccording to its self-reported version number, the remote installation of BIND is affected by multiple vulnerabilities : - Failure to clear existing RRSIG records when a NO DATA is negatively cached could cause subsequent lookups to crash named. (CVE-2010-3613) - Named, when acting as a DNSSEC validating resolver, could incorrectly mark zone data as insecure when the zone being queried is undergoing a key algorithm rollover. (CVE-2010-3614) - Using
    last seen2020-06-01
    descriptionThe security status of an NS RRset is not properly determined during a DNSKEY algorithm rollover which can allow a remote attacker to cause a denial of service. Signed negative responses and corresponding RRSIG records in the cache are not properly handled which can allow a remote attacker to cause a denial of service.
    last seen2020-06-01
