Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian Lenny DSA-2054-1 Critical Bind9 Cache Poisoning Advisory

debian
Calendar Grey June 4, 2010
Debian Logo
Urgent alert DSA-2054-1 for Debian highlighting vulnerabilities in bind9 that pose cache poisoning threats, necessitating prompt patching.
Several cache-poisoning vulnerabilities have been discovered in BIND

Summary

Several cache-poisoning vulnerabilities have been discovered in BIND.
These vulnerabilities are apply only if DNSSEC validation is enabled and
trust anchors have been installed, which is not the default.

The Common Vulnerabilities and Exposures project identifies the
following problems:

CVE-2010-0097
BIND does not properly validate DNSSEC NSEC records, which allows
remote attackers to add the Authenticated Data (AD) flag to a forged
NXDOMAIN response for an existing domain.

CVE-2010-0290
When processing crafted responses containing CNAME or DNAME records,
BIND is subject to a DNS cache poisoning vulnerability, provided that
DNSSEC validation is enabled and trust anchors have been installed.

CVE-2010-0382
When processing certain responses containing out-of-bailiwick data,
BIND is subject to a DNS cache poisoning vulnerability, provided that
DNSSEC validation is enabled and trust anchors have been installed.

In addition, this update introduce a more conservative query behavior
in the ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: bind9

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here