CVE-2009-0696
published 2009-07-29CVE-2009-0696: The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master…
PriorityP269medium4.3CVSS 2.0
AVNACMAuNCNINAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
12.65%
95.8th percentile
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.6.1.dfsg.P1-1 (bookworm) | bind9 1:9.6.1.dfsg.P1-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.6.1.dfsg.P1-1 | 1:9.6.1.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.6.1.dfsg.P1-1 | 1:9.6.1.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.6.1.dfsg.P1-1 | 1:9.6.1.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.6.1.dfsg.P1-1 | 1:9.6.1.dfsg.P1-1 |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted DNS dynamic update (opcode 0x2800) packets sent to port 53/UDP containing an ANY record type (0x00ff) in the prerequisite section; these can crash named regardless of allow-query or allow-update ACL configuration. ↗
- →Monitor named logs for the assertion failure string 'REQUIRE(type != ((dns_rdatatype_t)dns_rdatatype_any)) failed' followed by 'exiting (due to assertion failure)' as a definitive indicator of exploitation. ↗
- →The exploit process does not exit after sending the packet; a persistent sender repeatedly crashing named (if auto-restarted) is a behavioral indicator — look for rapid repeated named restarts correlated with a single source IP. ↗
- →IPs explicitly denied by allow-query can still trigger the crash; do not rely on BIND ACLs as a detection bypass indicator — any source IP sending the malformed dynamic update opcode to port 53/UDP is suspect. ↗
- →The exploit uses a fixed transaction ID of 0x1cd6 in the DNS header; this can be used as a packet-level signature for the specific PoC tool. ↗
- ·Configuring named to ignore dynamic updates is NOT sufficient to protect against this vulnerability; the assertion failure is triggered by the malformed packet before update permission checks occur. ↗
- ·Access controls (allow-query, allow-update) do not provide an effective workaround; the vulnerability affects all BIND 9 servers regardless of update configuration. ↗
- ·The only viable network-level mitigation is firewall-based blocking of DNS dynamic update (nsupdate) packets from reaching the nameserver on port 53/UDP. ↗
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vulncheck4.3MEDIUM
vendor_debian4.3HIGH
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Bind vulnerability
vendor_ubuntu·2009-07-29
CVE-2009-0696 Bind vulnerability
Title: Bind vulnerability
Summary: Bind vulnerability
Micha Krause discovered that Bind did not correctly validate certain
dynamic DNS update packets. An unauthenticated remote attacker could
send specially crafted traffic to crash the DNS server, leading to a
denial of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
BSD
FreeBSD-SA-09:12.bind: BIND named(8) dynamic update message remote DoS
bsd_advisories·2009-07-29·CVSS 4.3
CVE-2009-0696 [MEDIUM] FreeBSD-SA-09:12.bind: BIND named(8) dynamic update message remote DoS
FreeBSD-SA-09:12.bind Security Advisory
The FreeBSD Project
Topic: BIND named(8) dynamic update message remote DoS
Category: contrib
Module: bind
Announced: 2009-07-29
Credits: Matthias Urlichs
Affects: All supported versions of FreeBSD
Corrected: 2009-07-28 23:59:22 UTC (RELENG_7, 7.2-STABLE)
2009-07-29 00:14:14 UTC (RELENG_7_2, 7.2-RELEASE-p3)
2009-07-29 00:14:14 UTC (RELENG_7_1, 7.1-RELEASE-p7)
2009-07-29 00:13:47 UTC (RELENG_6, 6.4-STABLE)
2009-07-29 00:14:14 UTC (RELENG_6_4, 6.4-RELEASE-p6)
2009-07-29 00:14:14 UTC (RELENG_6_3, 6.3-RELEASE-p12)
CVE Name: CVE-2009-0696
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
NOTE: Due to this issue being accidentally discl
Red Hat
bind: DoS (assertion failure) via nsupdate packets
vendor_redhat·2009-07-28·CVSS 4.3
CVE-2009-0696 [MEDIUM] bind: DoS (assertion failure) via nsupdate packets
bind: DoS (assertion failure) via nsupdate packets
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message.
Debian
CVE-2009-0696: bind9 - The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P...
vendor_debian·2009·CVSS 4.3
CVE-2009-0696 [MEDIUM] CVE-2009-0696: bind9 - The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P...
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message.
Scope: local
bookworm: resolved (fixed in 1:9.6.1.dfsg.P1-1)
bullseye: resolved (fixed in 1:9.6.1.dfsg.P1-1)
forky: resolved (fixed in 1:9.6.1.dfsg.P1-1)
sid: resolved (fixed in 1:9.6.1.dfsg.P1-1)
trixie: resolved (fixed in 1:9.6.1.dfsg.P1-1)
GHSA
GHSA-54q7-wf84-v94r: The dns_db_findrdataset function in db
ghsa_unreviewed·2022-05-03
CVE-2009-0696 [MEDIUM] GHSA-54q7-wf84-v94r: The dns_db_findrdataset function in db
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.
OSV
CVE-2009-0696: The dns_db_findrdataset function in db
osv·2009-07-29·CVSS 4.3
CVE-2009-0696 [MEDIUM] CVE-2009-0696: The dns_db_findrdataset function in db
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message.
VulnCheck
ISC BIND dns_db_findrdataset Function Denial of Service
vulncheck·2009·CVSS 4.3
CVE-2009-0696 [MEDIUM] ISC BIND dns_db_findrdataset Function Denial of Service
ISC BIND dns_db_findrdataset Function Denial of Service
The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message.
Affected: isc bind
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://nvd.nist.gov/vuln/detail/CVE-2009-0696; https://www.cve.org/CVERecord?id=CVE-2009-0696
No detection rules found.
Bugzilla
CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry
bugzilla·2011-11-16·CVSS 4.3
CVE-2011-4313 [MEDIUM] CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry
CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry
A denial of service flaw was found in the way bind, a Berkeley Internet Name Domain (BIND) Domain Name System (DNS) server, performed processing of recursive queries for negative cache entries. A remote attacker could provide a specially-crafted DNS query, forcing the named server to process and log the error message, leading to named server crash. A different vulnerability than CVE-2009-0696 and CVE-2011-2464.
References:
[1] http://www.isc.org/software/bind/advisories/cve-2011-tbd
Discussion:
Created bind tracking bugs for this issue
Affects: fedora-all [bug 754509]
---
This is CVE-2011-4313.
---
*** Bug 754494 has been marked as a duplicate of this bug. ***
---
Any ETA for
Bugzilla
CVE-2009-0696 bind: DoS (assertion failure) via nsupdate packets
bugzilla·2009-07-28·CVSS 4.3
CVE-2009-0696 [MEDIUM] CVE-2009-0696 bind: DoS (assertion failure) via nsupdate packets
CVE-2009-0696 bind: DoS (assertion failure) via nsupdate packets
A Debian bug report [1] notes that named can be caused to exit with an assertion failure due to a particular update packet. This will cause a complete exit of named, preventing it from serving any more DNS responses.
The bug includes a reproducer in perl that can be used to trigger this. I have tried the reproducer against my local network LAN server (running CentOS 5.3) and it works as advertised, however there are a few factors that increase the complexity and reduce the exploitability of this issue. Because these are update packets, named must be setup to allow updating of records (which is typical in the case of dynamic DNS), however the RNDC key is required in order to perform the update; possibly if named is configure
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-013.txt.ascftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txthttp://aix.software.ibm.com/aix/efixes/security/bind_advisory.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975http://secunia.com/advisories/36035http://secunia.com/advisories/36038http://secunia.com/advisories/36050http://secunia.com/advisories/36053http://secunia.com/advisories/36056http://secunia.com/advisories/36063http://secunia.com/advisories/36086http://secunia.com/advisories/36098http://secunia.com/advisories/36192http://secunia.com/advisories/37471http://secunia.com/advisories/39334http://sunsolve.sun.com/search/document.do?assetkey=1-26-264828-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020788.1-1http://up2date.astaro.com/2009/08/up2date_7505_released.htmlhttp://wiki.rpath.com/Advisories:rPSA-2009-0113http://www.kb.cert.org/vuls/id/725188http://www.openbsd.org/errata44.html#014_bindhttp://www.securityfocus.com/archive/1/505403/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securitytracker.com/id?1022613http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561499http://www.ubuntu.com/usn/usn-808-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/2036http://www.vupen.com/english/advisories/2009/2088http://www.vupen.com/english/advisories/2009/2171http://www.vupen.com/english/advisories/2009/2247http://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10414https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12245https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7806https://www.isc.org/node/474https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01265.htmlftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-013.txt.ascftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txthttp://aix.software.ibm.com/aix/efixes/security/bind_advisory.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975http://secunia.com/advisories/36035http://secunia.com/advisories/36038http://secunia.com/advisories/36050http://secunia.com/advisories/36053http://secunia.com/advisories/36056http://secunia.com/advisories/36063http://secunia.com/advisories/36086http://secunia.com/advisories/36098http://secunia.com/advisories/36192http://secunia.com/advisories/37471http://secunia.com/advisories/39334http://sunsolve.sun.com/search/document.do?assetkey=1-26-264828-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020788.1-1http://up2date.astaro.com/2009/08/up2date_7505_released.htmlhttp://wiki.rpath.com/Advisories:rPSA-2009-0113http://www.kb.cert.org/vuls/id/725188http://www.openbsd.org/errata44.html#014_bindhttp://www.securityfocus.com/archive/1/505403/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securitytracker.com/id?1022613http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561499http://www.ubuntu.com/usn/usn-808-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/2036http://www.vupen.com/english/advisories/2009/2088http://www.vupen.com/english/advisories/2009/2171http://www.vupen.com/english/advisories/2009/2247http://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10414https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12245https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7806https://www.isc.org/node/474https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01265.html
2009-07-29
Published
Exploited in the wild