Vulnerabilities > CVE-2012-5166 - Numeric Errors vulnerability in ISC Bind

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
isc
CWE-189
nessus

Summary

ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-2560.NASL
    descriptionIt was discovered that BIND, a DNS server, hangs while constructing the additional section of a DNS reply, when certain combinations of resource records are present. This vulnerability affects both recursive and authoritative servers.
    last seen2020-03-17
    modified2012-10-22
    plugin id62643
    published2012-10-22
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62643
    titleDebian DSA-2560-1 : bind9 - denial of service
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2012-15965.NASL
    descriptionUpdate to the latest BIND packages to fix CVE-2012-5166 and incorporate other fixes from upstream. Packages dhcp, bind-dyndb-ldap and dnsperf were rebuilt. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2012-10-22
    plugin id62646
    published2012-10-22
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62646
    titleFedora 17 : bind-9.9.2-2.fc17 / bind-dyndb-ldap-1.1.0-0.15.rc1.fc17 / dhcp-4.2.4-16.P2.fc17 / etc (2012-15965)
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV30368.NASL
    descriptionIf specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id63749
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/63749
    titleAIX 5.3 TL 12 : bind9 (IV30368)
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV30367.NASL
    descriptionIf specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id63748
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/63748
    titleAIX 7.1 TL 1 : bind9 (IV30367)
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2012-1363.NASL
    descriptionUpdated bind packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. A flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166) Users of bind are advised to upgrade to these updated packages, which correct this issue. After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-06-01
    modified2020-06-02
    plugin id62543
    published2012-10-15
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62543
    titleRHEL 5 / 6 : bind (RHSA-2012:1363)
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV30366.NASL
    descriptionIf specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id63747
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/63747
    titleAIX 7.1 TL 0 : bind9 (IV30366)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U855824.NASL
    descriptionThe remote host is missing AIX PTF U855824, which is related to the security of the package bos.net.tcp.server. If specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id66279
    published2013-05-01
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/66279
    titleAIX 7.1 TL 1 : bos.net.tcp.server (U855824)
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS11_BIND_20130129_2.NASL
    descriptionThe remote Solaris system is missing necessary patches to address security updates : - ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records. (CVE-2012-5166)
    last seen2020-06-01
    modified2020-06-02
    plugin id80595
    published2015-01-19
    reporterThis script is Copyright (C) 2015-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/80595
    titleOracle Solaris Third-Party Patch Update : bind (cve_2012_5166_denial_of)
  • NASL familyAmazon Linux Local Security Checks
    NASL idALA_ALAS-2012-138.NASL
    descriptionA flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166)
    last seen2020-06-01
    modified2020-06-02
    plugin id69628
    published2013-09-04
    reporterThis script is Copyright (C) 2013-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/69628
    titleAmazon Linux AMI : bind (ALAS-2012-138)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2012-16022.NASL
    descriptionUpdate to the latest BIND packages to fix CVE-2012-5166 and incorporate other fixes from upstream. Packages dhcp, bind-dyndb-ldap and dnsperf were rebuilt. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2012-10-22
    plugin id62647
    published2012-10-22
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62647
    titleFedora 18 : bind-dyndb-ldap-2.0-0.3.20121009git6a86b1.fc18 / bind-9.9.2-2.fc18 / etc (2012-16022)
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_SECUPD2013-004.NASL
    descriptionThe remote host is running a version of Mac OS X 10.6 or 10.7 that does not have Security Update 2013-004 applied. This update contains several security-related fixes for the following component : - Apache - Bind - Certificate Trust Policy - ClamAV - Installer - IPSec - Mobile Device Management - OpenSSL - PHP - PostgreSQL - QuickTime - sudo Note that successful exploitation of the most serious issues could result in arbitrary code execution.
    last seen2020-06-01
    modified2020-06-02
    plugin id69878
    published2013-09-13
    reporterThis script is Copyright (C) 2013-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/69878
    titleMac OS X Multiple Vulnerabilities (Security Update 2013-004)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U855334.NASL
    descriptionThe remote host is missing AIX PTF U855334, which is related to the security of the package bos.net.tcp.server.
    last seen2020-06-01
    modified2020-06-02
    plugin id71165
    published2013-12-03
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/71165
    titleAIX 6.1 TL 9 : bos.net.tcp.server (U855334)
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2012-1364.NASL
    descriptionUpdated bind97 packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. A flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166) Users of bind97 are advised to upgrade to these updated packages, which correct this issue. After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-06-01
    modified2020-06-02
    plugin id62544
    published2012-10-15
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62544
    titleRHEL 5 : bind97 (RHSA-2012:1364)
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_10_8_5.NASL
    descriptionThe remote host is running a version of Mac OS X 10.8.x that is prior to 10.8.5. The newer version contains multiple security-related fixes for the following components : - Apache - Bind - Certificate Trust Policy - CoreGraphics - ImageIO - Installer - IPSec - Kernel - Mobile Device Management - OpenSSL - PHP - PostgreSQL - Power Management - QuickTime - Screen Lock - sudo This update also addresses an issue in which certain Unicode strings could cause applications to unexpectedly quit. Note that successful exploitation of the most serious issues could result in arbitrary code execution.
    last seen2020-06-01
    modified2020-06-02
    plugin id69877
    published2013-09-13
    reporterThis script is Copyright (C) 2013-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/69877
    titleMac OS X 10.8.x < 10.8.5 Multiple Vulnerabilities
  • NASL familyOracleVM Local Security Checks
    NASL idORACLEVM_OVMSA-2016-0055.NASL
    descriptionThe remote OracleVM system is missing necessary patches to address critical security updates : - Fix issue with patch for CVE-2016-1285 and CVE-2016-1286 found by test suite - Fix (CVE-2016-1285, CVE-2016-1286) - Fix (CVE-2015-8704) - Fix (CVE-2015-8000) - Fix (CVE-2015-5722) - Fix (CVE-2015-5477) - Remove files backup after patching (Related: #1171971) - Fix CVE-2014-8500 (#1171971) - fix race condition in socket module - fix (CVE-2012-5166) - bind-chroot-admin: set correct permissions on /etc/named.conf during update - fix (CVE-2012-4244) - fix (CVE-2012-3817) - fix (CVE-2012-1667) - fix (CVE-2012-1033)
    last seen2020-06-01
    modified2020-06-02
    plugin id91739
    published2016-06-22
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/91739
    titleOracleVM 3.2 : bind (OVMSA-2016-0055)
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2012-1364.NASL
    descriptionFrom Red Hat Security Advisory 2012:1364 : Updated bind97 packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. A flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166) Users of bind97 are advised to upgrade to these updated packages, which correct this issue. After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-06-01
    modified2020-06-02
    plugin id68641
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/68641
    titleOracle Linux 5 : bind97 (ELSA-2012-1364)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_BIND-121015.NASL
    descriptionThe following issue has been fixed : - Specially crafted RDATA could have caused bind to lockup. This is a different flaw than CVE-2012-4244.
    last seen2020-06-05
    modified2013-01-25
    plugin id64115
    published2013-01-25
    reporterThis script is Copyright (C) 2013-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/64115
    titleSuSE 11.2 Security Update : bind (SAT Patch Number 6944)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2013-296.NASL
    descriptionbind was updated to 9.8.4-P2 to fix security problems and bugs. Security Fixes Removed the check for regex.h in configure in order to disable regex syntax checking, as it exposes BIND to a critical flaw in libregex on some platforms. [CVE-2013-2266] [RT #32688] https://kb.isc.org/article/AA-00871 (bnc#811876) Prevents named from aborting with a require assertion failure on servers with DNS64 enabled. These crashes might occur as a result of specific queries that are received. (Note that this fix is a subset of a series of updates that will be included in full in BIND 9.8.5 and 9.9.3 as change #3388, RT #30996). [CVE-2012-5688] [RT #30792] A deliberately constructed combination of records could cause named to hang while populating the additional section of a response. [CVE-2012-5166] [RT #31090] Prevents a named assert (crash) when queried for a record whose RDATA exceeds 65535 bytes [CVE-2012-4244] [RT #30416] Prevents a named assert (crash) when validating caused by using
    last seen2020-06-05
    modified2014-06-13
    plugin id74953
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/74953
    titleopenSUSE Security Update : bind (openSUSE-SU-2013:0605-1)
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2012-1364.NASL
    descriptionUpdated bind97 packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. A flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166) Users of bind97 are advised to upgrade to these updated packages, which correct this issue. After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-06-01
    modified2020-06-02
    plugin id62524
    published2012-10-15
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62524
    titleCentOS 5 : bind97 (CESA-2012:1364)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2012-716.NASL
    descriptionThe bind nameserver was updated to fix specially crafted DNS data can cause a lockup in named.
    last seen2020-06-05
    modified2014-06-13
    plugin id74782
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/74782
    titleopenSUSE Security Update : bind (openSUSE-SU-2012:1372-1)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_BIND-8322.NASL
    descriptionThe following issue has been fixed : - Specially crafted RDATA could have caused bind to lockup. A different flaw than CVE-2012-4244.
    last seen2020-06-05
    modified2012-10-24
    plugin id62674
    published2012-10-24
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62674
    titleSuSE 10 Security Update : bind (ZYPP Patch Number 8322)
  • NASL familySlackware Local Security Checks
    NASL idSLACKWARE_SSA_2012-341-01.NASL
    descriptionNew bind packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, 14.0, and -current to fix security issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id63167
    published2012-12-07
    reporterThis script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/63167
    titleSlackware 12.1 / 12.2 / 13.0 / 13.1 / 13.37 / 14.0 / current : bind (SSA:2012-341-01)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_4B79538BA45011E29898001060E06FD4.NASL
    descriptionProblem description : The BIND daemon would crash when a query is made on a resource record with RDATA that exceeds 65535 bytes. The BIND daemon would lock up when a query is made on specific combinations of RDATA.
    last seen2020-06-01
    modified2020-06-02
    plugin id65967
    published2013-04-14
    reporterThis script is Copyright (C) 2013-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/65967
    titleFreeBSD : FreeBSD -- Multiple Denial of Service vulnerabilities with named(8) (4b79538b-a450-11e2-9898-001060e06fd4)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_57A700F912C011E29F86001D923933B6.NASL
    descriptionISC reports : A deliberately constructed combination of records could cause named to hang while populating the additional section of a response.
    last seen2020-06-01
    modified2020-06-02
    plugin id62489
    published2012-10-11
    reporterThis script is Copyright (C) 2012-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62489
    titleFreeBSD : dns/bind9* -- crash on deliberately constructed combination of records (57a700f9-12c0-11e2-9f86-001d923933b6)
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2012-1365.NASL
    descriptionDescription of changes: [20:9.2.4-38.0.2.el4] - fix CVE-2012-4244 (Adam Tkac) [orabz 14518] - fix CVE-2012-5166 (Adam Tkac) [orabz 14518]
    last seen2020-06-01
    modified2020-06-02
    plugin id68642
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/68642
    titleOracle Linux 4 : bind (ELSA-2012-1365)
  • NASL familyMandriva Local Security Checks
    NASL idMANDRIVA_MDVSA-2012-162.NASL
    descriptionA vulnerability was discovered and corrected in bind : A certain combination of records in the RBT could cause named to hang while populating the additional section of a response. [RT #31090] (CVE-2012-5166). The updated packages have been upgraded to bind 9.7.6-P4 and 9.8.3-P4 which is not vulnerable to this issue.
    last seen2020-06-01
    modified2020-06-02
    plugin id62491
    published2012-10-11
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62491
    titleMandriva Linux Security Advisory : bind (MDVSA-2012:162)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U857842.NASL
    descriptionThe remote host is missing AIX PTF U857842, which is related to the security of the package bos.net.tcp.server. If specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id66280
    published2013-05-01
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/66280
    titleAIX 7.1 : bos.net.tcp.server (U857842)
  • NASL familyOracleVM Local Security Checks
    NASL idORACLEVM_OVMSA-2020-0021.NASL
    descriptionThe remote OracleVM system is missing necessary patches to address critical security updates : please see Oracle VM Security Advisory OVMSA-2020-0021 for details.
    last seen2020-06-10
    modified2020-06-05
    plugin id137170
    published2020-06-05
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/137170
    titleOracleVM 3.3 / 3.4 : bind (OVMSA-2020-0021)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2012-15981.NASL
    descriptionUpdate to the latest BIND packages to fix CVE-2012-5166 and incorporate other fixes from upstream. Packages dhcp, bind-dyndb-ldap and dnsperf were rebuilt. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2012-10-23
    plugin id62656
    published2012-10-23
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62656
    titleFedora 16 : bind-9.8.4-2.fc16 / bind-dyndb-ldap-1.1.0-0.15.rc1.fc16 / dhcp-4.2.4-4.P2.fc16 / etc (2012-15981)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20121012_BIND_ON_SL5_X.NASL
    descriptionA flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166) After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-03-18
    modified2012-10-16
    plugin id62555
    published2012-10-16
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62555
    titleScientific Linux Security Update : bind on SL5.x, SL6.x i386/x86_64 (20121012)
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV30364.NASL
    descriptionIf specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id63745
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/63745
    titleAIX 6.1 TL 6 : bind9 (IV30364)
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2012-1363.NASL
    descriptionFrom Red Hat Security Advisory 2012:1363 : Updated bind packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. A flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166) Users of bind are advised to upgrade to these updated packages, which correct this issue. After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-06-01
    modified2020-06-02
    plugin id68640
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/68640
    titleOracle Linux 5 / 6 : bind (ELSA-2012-1363)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U854732.NASL
    descriptionThe remote host is missing AIX PTF U854732, which is related to the security of the package bos.net.tcp.server. If specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id65710
    published2013-03-28
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/65710
    titleAIX 6.1 TL 6 : bos.net.tcp.server (U854732)
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2012-1363.NASL
    descriptionUpdated bind packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. A flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166) Users of bind are advised to upgrade to these updated packages, which correct this issue. After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-06-01
    modified2020-06-02
    plugin id62523
    published2012-10-15
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62523
    titleCentOS 5 / 6 : bind (CESA-2012:1363)
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-1601-1.NASL
    descriptionJake Montgomery discovered that Bind incorrectly handled certain specific combinations of RDATA. A remote attacker could use this flaw to cause Bind to crash, resulting in a denial of service. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id62495
    published2012-10-11
    reporterUbuntu Security Notice (C) 2012-2019 Canonical, Inc. / NASL script (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62495
    titleUbuntu 8.04 LTS / 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : bind9 vulnerability (USN-1601-1)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20121012_BIND97_ON_SL5_X.NASL
    descriptionA flaw was found in the way BIND handled certain combinations of resource records. A remote attacker could use this flaw to cause a recursive resolver, or an authoritative server in certain configurations, to lockup. (CVE-2012-5166) After installing the update, the BIND daemon (named) will be restarted automatically.
    last seen2020-03-18
    modified2012-10-16
    plugin id62554
    published2012-10-16
    reporterThis script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/62554
    titleScientific Linux Security Update : bind97 on SL5.x i386/x86_64 (20121012)
  • NASL familyOracleVM Local Security Checks
    NASL idORACLEVM_OVMSA-2017-0066.NASL
    descriptionThe remote OracleVM system is missing necessary patches to address critical security updates : - Fix CVE-2017-3136 (ISC change 4575) - Fix CVE-2017-3137 (ISC change 4578) - Fix and test caching CNAME before DNAME (ISC change 4558) - Fix CVE-2016-9147 (ISC change 4510) - Fix regression introduced by CVE-2016-8864 (ISC change 4530) - Restore SELinux contexts before named restart - Use /lib or /lib64 only if directory in chroot already exists - Tighten NSS library pattern, escape chroot mount path - Fix (CVE-2016-8864) - Do not change lib permissions in chroot (#1321239) - Support WKS records in chroot (#1297562) - Do not include patch backup in docs (fixes #1325081 patch) - Backported relevant parts of [RT #39567] (#1259923) - Increase ISC_SOCKET_MAXEVENTS to 2048 (#1326283) - Fix multiple realms in nsupdate script like upstream (#1313286) - Fix multiple realm in nsupdate script (#1313286) - Use resolver-query-timeout high enough to recover all forwarders (#1325081) - Fix (CVE-2016-2848) - Fix infinite loop in start_lookup (#1306504) - Fix (CVE-2016-2776)
    last seen2020-06-01
    modified2020-06-02
    plugin id99569
    published2017-04-21
    reporterThis script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/99569
    titleOracleVM 3.3 / 3.4 : bind (OVMSA-2017-0066)
  • NASL familyF5 Networks Local Security Checks
    NASL idF5_BIGIP_SOL14201.NASL
    descriptionA vulnerability exists in the BIND DNS server process that may allow a remote attacker to initiate a denial-of-service (DoS) attack against the DNS service.
    last seen2020-06-01
    modified2020-06-02
    plugin id78143
    published2014-10-10
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/78143
    titleF5 Networks BIG-IP : BIND denial-of-service attack (SOL14201)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U854646.NASL
    descriptionThe remote host is missing AIX PTF U854646, which is related to the security of the package bos.net.tcp.server. If specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id65709
    published2013-03-28
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/65709
    titleAIX 6.1 TL 7 : bos.net.tcp.server (U854646)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-201401-34.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-201401-34 (BIND: Denial of Service) Multiple vulnerabilities have been discovered in BIND. Please review the CVE identifiers referenced below for details. Impact : A remote attacker may be able to cause a Denial of Service condition. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id72208
    published2014-01-30
    reporterThis script is Copyright (C) 2014-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/72208
    titleGLSA-201401-34 : BIND: Denial of Service
  • NASL familyDNS
    NASL idBIND9_991_P4.NASL
    descriptionAccording to its self-reported version number, the remote installation of BIND can become locked up if certain combinations of RDATA are loaded into the server. Note that Nessus has only relied on the version itself and has not attempted to determine whether or not the install is actually affected.
    last seen2020-06-01
    modified2020-06-02
    plugin id62562
    published2012-10-16
    reporterThis script is Copyright (C) 2012-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/62562
    titleISC BIND 9 DNS RDATA Handling DoS
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV30365.NASL
    descriptionIf specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
    last seen2020-06-01
    modified2020-06-02
    plugin id63746
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/63746
    titleAIX 6.1 TL 7 : bind9 (IV30365)

Oval

accepted2014-01-06T04:00:29.972-05:00
classvulnerability
contributors
nameChandan M C
organizationHewlett-Packard
definition_extensions
  • commentIBM AIX 5300-12 is installed
    ovaloval:org.mitre.oval:def:18390
  • commentIBM AIX 6100-06 is installed
    ovaloval:org.mitre.oval:def:19197
  • commentIBM AIX 6100-07 is installed
    ovaloval:org.mitre.oval:def:19105
  • commentIBM AIX 6100-08 is installed
    ovaloval:org.mitre.oval:def:19215
  • commentIBM AIX 7100-00 is installed
    ovaloval:org.mitre.oval:def:19195
  • commentIBM AIX 7100-01 is installed
    ovaloval:org.mitre.oval:def:19029
  • commentIBM AIX 7100-02 is installed
    ovaloval:org.mitre.oval:def:19343
descriptionISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.
familyunix
idoval:org.mitre.oval:def:19706
statusaccepted
submitted2013-11-18T10:06:56.357-05:00
titleVulnerability in AIX bind
version49

Redhat

advisories
  • bugzilla
    id864273
    titleCVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named
    oval
    OR
    • commentRed Hat Enterprise Linux must be installed
      ovaloval:com.redhat.rhba:tst:20070304026
    • AND
      • commentRed Hat Enterprise Linux 5 is installed
        ovaloval:com.redhat.rhba:tst:20070331005
      • OR
        • AND
          • commentbind-sdb is earlier than 30:9.3.6-20.P1.el5_8.5
            ovaloval:com.redhat.rhsa:tst:20121363001
          • commentbind-sdb is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070057010
        • AND
          • commentbind-utils is earlier than 30:9.3.6-20.P1.el5_8.5
            ovaloval:com.redhat.rhsa:tst:20121363003
          • commentbind-utils is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070057014
        • AND
          • commentbind-libs is earlier than 30:9.3.6-20.P1.el5_8.5
            ovaloval:com.redhat.rhsa:tst:20121363005
          • commentbind-libs is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070057002
        • AND
          • commentbind is earlier than 30:9.3.6-20.P1.el5_8.5
            ovaloval:com.redhat.rhsa:tst:20121363007
          • commentbind is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070057016
        • AND
          • commentcaching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.5
            ovaloval:com.redhat.rhsa:tst:20121363009
          • commentcaching-nameserver is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070057004
        • AND
          • commentbind-devel is earlier than 30:9.3.6-20.P1.el5_8.5
            ovaloval:com.redhat.rhsa:tst:20121363011
          • commentbind-devel is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070057012
        • AND
          • commentbind-chroot is earlier than 30:9.3.6-20.P1.el5_8.5
            ovaloval:com.redhat.rhsa:tst:20121363013
          • commentbind-chroot is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070057008
        • AND
          • commentbind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.5
            ovaloval:com.redhat.rhsa:tst:20121363015
          • commentbind-libbind-devel is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070057006
    • AND
      • commentRed Hat Enterprise Linux 6 is installed
        ovaloval:com.redhat.rhba:tst:20111656003
      • OR
        • AND
          • commentbind is earlier than 32:9.8.2-0.10.rc1.el6_3.5
            ovaloval:com.redhat.rhsa:tst:20121363018
          • commentbind is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhba:tst:20170651006
        • AND
          • commentbind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.5
            ovaloval:com.redhat.rhsa:tst:20121363020
          • commentbind-libs is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhba:tst:20170651010
        • AND
          • commentbind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.5
            ovaloval:com.redhat.rhsa:tst:20121363022
          • commentbind-utils is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhba:tst:20170651012
        • AND
          • commentbind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.5
            ovaloval:com.redhat.rhsa:tst:20121363024
          • commentbind-chroot is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhba:tst:20170651008
        • AND
          • commentbind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.5
            ovaloval:com.redhat.rhsa:tst:20121363026
          • commentbind-devel is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhba:tst:20170651004
        • AND
          • commentbind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.5
            ovaloval:com.redhat.rhsa:tst:20121363028
          • commentbind-sdb is signed with Red Hat redhatrelease2 key
            ovaloval:com.redhat.rhba:tst:20170651002
    rhsa
    idRHSA-2012:1363
    released2012-10-12
    severityImportant
    titleRHSA-2012:1363: bind security update (Important)
  • bugzilla
    id864273
    titleCVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named
    oval
    OR
    • commentRed Hat Enterprise Linux must be installed
      ovaloval:com.redhat.rhba:tst:20070304026
    • AND
      • commentRed Hat Enterprise Linux 5 is installed
        ovaloval:com.redhat.rhba:tst:20070331005
      • OR
        • AND
          • commentbind97-utils is earlier than 32:9.7.0-10.P2.el5_8.4
            ovaloval:com.redhat.rhsa:tst:20121364001
          • commentbind97-utils is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20110845004
        • AND
          • commentbind97-devel is earlier than 32:9.7.0-10.P2.el5_8.4
            ovaloval:com.redhat.rhsa:tst:20121364003
          • commentbind97-devel is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20110845006
        • AND
          • commentbind97-chroot is earlier than 32:9.7.0-10.P2.el5_8.4
            ovaloval:com.redhat.rhsa:tst:20121364005
          • commentbind97-chroot is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20110845010
        • AND
          • commentbind97 is earlier than 32:9.7.0-10.P2.el5_8.4
            ovaloval:com.redhat.rhsa:tst:20121364007
          • commentbind97 is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20110845002
        • AND
          • commentbind97-libs is earlier than 32:9.7.0-10.P2.el5_8.4
            ovaloval:com.redhat.rhsa:tst:20121364009
          • commentbind97-libs is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20110845008
    rhsa
    idRHSA-2012:1364
    released2012-10-12
    severityImportant
    titleRHSA-2012:1364: bind97 security update (Important)
  • rhsa
    idRHSA-2012:1365
rpms
  • bind-30:9.3.6-20.P1.el5_8.5
  • bind-32:9.8.2-0.10.rc1.el6_3.5
  • bind-chroot-30:9.3.6-20.P1.el5_8.5
  • bind-chroot-32:9.8.2-0.10.rc1.el6_3.5
  • bind-debuginfo-30:9.3.6-20.P1.el5_8.5
  • bind-debuginfo-32:9.8.2-0.10.rc1.el6_3.5
  • bind-devel-30:9.3.6-20.P1.el5_8.5
  • bind-devel-32:9.8.2-0.10.rc1.el6_3.5
  • bind-libbind-devel-30:9.3.6-20.P1.el5_8.5
  • bind-libs-30:9.3.6-20.P1.el5_8.5
  • bind-libs-32:9.8.2-0.10.rc1.el6_3.5
  • bind-sdb-30:9.3.6-20.P1.el5_8.5
  • bind-sdb-32:9.8.2-0.10.rc1.el6_3.5
  • bind-utils-30:9.3.6-20.P1.el5_8.5
  • bind-utils-32:9.8.2-0.10.rc1.el6_3.5
  • caching-nameserver-30:9.3.6-20.P1.el5_8.5
  • bind97-32:9.7.0-10.P2.el5_8.4
  • bind97-chroot-32:9.7.0-10.P2.el5_8.4
  • bind97-debuginfo-32:9.7.0-10.P2.el5_8.4
  • bind97-devel-32:9.7.0-10.P2.el5_8.4
  • bind97-libs-32:9.7.0-10.P2.el5_8.4
  • bind97-utils-32:9.7.0-10.P2.el5_8.4
  • bind-20:9.2.4-41.el4
  • bind-chroot-20:9.2.4-41.el4
  • bind-debuginfo-20:9.2.4-41.el4
  • bind-devel-20:9.2.4-41.el4
  • bind-libs-20:9.2.4-41.el4
  • bind-utils-20:9.2.4-41.el4

References