Vulnerabilities > CVE-2012-2979 - Incorrect Resource Transfer Between Spheres vulnerability in Freebsd Name Server Daemon
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Fedora Local Security Checks NASL id FEDORA_2012-11207.NASL description Updated upstream releasee for CVE-2012-2979 / VU#517036, our packages were not vulnerable Fix for CVE-2012-2978: NSD denial of service vulnerability from non-standard DNS packet from any host Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-03-17 modified 2012-08-10 plugin id 61470 published 2012-08-10 reporter This script is Copyright (C) 2012-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/61470 title Fedora 16 : nsd-3.2.13-1.fc16 (2012-11207) NASL family FreeBSD Local Security Checks NASL id FREEBSD_PKG_17F369DCD7E711E190A2000C299B62E1.NASL description Tom Hendrikx reports : It is possible to crash (SIGSEGV) a NSD child server process by sending it a DNS packet from any host on the internet and the per zone stats build option is enabled. A crashed child process will automatically be restarted by the parent process, but an attacker may keep the NSD server occupied restarting child processes by sending it a stream of such packets effectively preventing the NSD server to serve. last seen 2020-06-01 modified 2020-06-02 plugin id 60150 published 2012-07-30 reporter This script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/60150 title FreeBSD : nsd -- Denial of Service (17f369dc-d7e7-11e1-90a2-000c299b62e1) NASL family Fedora Local Security Checks NASL id FEDORA_2012-11203.NASL description Updated upstream releasee for CVE-2012-2979 / VU#517036, our packages were not vulnerable Fix for CVE-2012-2978: NSD denial of service vulnerability from non-standard DNS packet from any host Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-03-17 modified 2012-08-10 plugin id 61469 published 2012-08-10 reporter This script is Copyright (C) 2012-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/61469 title Fedora 17 : nsd-3.2.13-1.fc17 (2012-11203)
References
- https://security-tracker.debian.org/tracker/CVE-2012-2979
- https://security-tracker.debian.org/tracker/CVE-2012-2979
- https://vuxml.freebsd.org/freebsd/17f369dc-d7e7-11e1-90a2-000c299b62e1.html
- https://vuxml.freebsd.org/freebsd/17f369dc-d7e7-11e1-90a2-000c299b62e1.html
- https://www.tenable.com/plugins/nessus/60150
- https://www.tenable.com/plugins/nessus/60150