Vulnerabilities > CVE-2012-2979 - Incorrect Resource Transfer Between Spheres vulnerability in Freebsd Name Server Daemon

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
freebsd
CWE-669
nessus

Summary

FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.

Vulnerable Configurations

Part Description Count
Application
Freebsd
53

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2012-11207.NASL
    descriptionUpdated upstream releasee for CVE-2012-2979 / VU#517036, our packages were not vulnerable Fix for CVE-2012-2978: NSD denial of service vulnerability from non-standard DNS packet from any host Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2012-08-10
    plugin id61470
    published2012-08-10
    reporterThis script is Copyright (C) 2012-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/61470
    titleFedora 16 : nsd-3.2.13-1.fc16 (2012-11207)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_17F369DCD7E711E190A2000C299B62E1.NASL
    descriptionTom Hendrikx reports : It is possible to crash (SIGSEGV) a NSD child server process by sending it a DNS packet from any host on the internet and the per zone stats build option is enabled. A crashed child process will automatically be restarted by the parent process, but an attacker may keep the NSD server occupied restarting child processes by sending it a stream of such packets effectively preventing the NSD server to serve.
    last seen2020-06-01
    modified2020-06-02
    plugin id60150
    published2012-07-30
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/60150
    titleFreeBSD : nsd -- Denial of Service (17f369dc-d7e7-11e1-90a2-000c299b62e1)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2012-11203.NASL
    descriptionUpdated upstream releasee for CVE-2012-2979 / VU#517036, our packages were not vulnerable Fix for CVE-2012-2978: NSD denial of service vulnerability from non-standard DNS packet from any host Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2012-08-10
    plugin id61469
    published2012-08-10
    reporterThis script is Copyright (C) 2012-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/61469
    titleFedora 17 : nsd-3.2.13-1.fc17 (2012-11203)