Cybertrion Systems

[2/5] ISC BIND libbind “inet_network()” Off-By-One Vulnerability

January 21st, 2008 by
[2/5] ISC BIND libbind “inet_network()” Off-By-One Vulnerability

:A vulnerability has been reported in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.The vulnerability affects applications linked against libbind and is related to:SA28367NOTE: The applications included in BIND 8 and 9 do not call the vulnerable function.The vulnerability is reported in the following versions:* BIND 8 (all versions)* BIND 9.0 (all versions)* BIND 9.1 (all versions)* BIND 9.2 (all versions)* BIND 9.3.0, 9.3.1, 9.3.2, 9.3.3, and 9.3.4* BIND 9.4.0, 9.4.1, and 9.4.2* BIND 9.5.0a1, 9.5.0a2, 9.5.0a3, 9.5.0a4, 9.5.0a5, 9.5.0a6, 9.5.0a7, and 9.5.0b1Solution:Please see vendor advisory for patch information.Provided and/or discovered by:The vendor credits Nate Eldredge.Original Advisory:http://www.isc.org/index.pl?/sw/bind/bind-security.phpOther References:SA28367:http://secunia.com/advisories/28367/

Original post by manisha

[2/5] ISC BIND libbind “inet_network()” Off-By-One Vulnerability

Related Articles:
  • [3/5] BIND Predictable DNS Query IDs Vulnerability
  • [2/5] Fedora update for bind
  • [3/5] Mandriva update for bind
  • [3/5] Slackware update for bind
  • [2/5] Fedora BIND “/etc/rndc.key” Insecure File Permissions


  • Posted in Advisories - Exploits | | [2/5] ISC BIND libbind “inet_network()” Off-By-One Vulnerability

    << [4/5] Toshiba Surveillix RecordSend Class ActiveX Control Buffer Overflows | [3/5] Debian update for horde3 >>