Subscribe to Windows IT Pro
January 29, 2001 12:00 AM

Multiple Vulnerabilities in BIND

Windows IT Pro
InstantDoc ID #19812
Rating: (0)

Reported January 29, 2001, by CERT.

VERSIONS AFFECTED
  • BIND 8
  • BIND 4

DESCRIPTION

Multiple vulnerabilities have been discovered in Internet Software Consortium (ISC) BIND versions 4 and 8. In the first vulnerability, in BIND 8, a remote buffer overflow can let an attacker execute arbitrary code without having control over a DNS server. The second vulnerability, in BIND 4, is also a buffer overflow that requires the attacker to have control over a DNS server to execute arbitrary code. In the third vulnerability, also in BIND 4, an attacker can use a format string issue to launch arbitrary commands.

VENDOR RESPONSE

ISC is aware of these issues and has released patches. BIND 4.9.8 and 8.2.3 address the vulnerabilities.

CREDIT
Discovered by
Covert Labs.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.