CVE-2012-1033
published 2012-02-08CVE-2012-1033: The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
13.54%
96.1th percentile
The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.1.dfsg.P1-4.1 (bookworm) | bind9 1:9.8.1.dfsg.P1-4.1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware security updates for vSphere API and ESX Service Console
vendor_vmware·2012-11-15·CVSS 5.0
CVE-2011-4940 [MEDIUM] VMware security updates for vSphere API and ESX Service Console
VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
a. VMware vSphere API denial of service vulnerability The VMware vSphere API contains a denial of service vulnerability. This issue allows an unauthenticated user to send a maliciously crafted API request and disable the host daemon. Exploitation of the issue would prevent management activities on the host but any virtual machines running on the host would be unaffected. VMware would like to thank Sebastián Tello of Core Security Technologies for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-5703 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is a
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2012-06-05·CVSS 5.0
CVE-2012-1033 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Dan Luther discovered that Bind incorrectly handled zero length rdata
fields. A remote attacker could use this flaw to cause Bind to crash or
behave erratically, resulting in a denial of service. (CVE-2012-1667)
It was discovered that Bind incorrectly handled revoked domain names. A
remote attacker could use this flaw to cause malicious domain names to be
continuously resolvable even after they have been revoked. (CVE-2012-1033)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: deleted domain name resolving flaw
vendor_redhat·2012-02-07·CVSS 5.0
CVE-2012-1033 [MEDIUM] bind: deleted domain name resolving flaw
bind: deleted domain name resolving flaw
The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
Package: bind (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2012-1033: bind9 - The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and T...
vendor_debian·2012·CVSS 5.0
CVE-2012-1033 [MEDIUM] CVE-2012-1033: bind9 - The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and T...
The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
forky: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
sid: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
trixie: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
GHSA
GHSA-g63p-j554-jxp4: The resolver in ISC BIND 9 through 9
ghsa_unreviewed·2022-05-14
CVE-2012-1033 [MEDIUM] GHSA-g63p-j554-jxp4: The resolver in ISC BIND 9 through 9
The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
OSV
CVE-2012-1033: The resolver in ISC BIND 9 through 9
osv·2012-02-08·CVSS 5.0
CVE-2012-1033 [MEDIUM] CVE-2012-1033: The resolver in ISC BIND 9 through 9
The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
No detection rules found.
Unit42
Leveraging DNS Tunneling for Tracking and Scanning
blogs_unit42·2024-05-13
Leveraging DNS Tunneling for Tracking and Scanning
## Executive Summary
This article presents a case study on new applications of domain name system (DNS) tunneling we have found in the wild. These techniques expand beyond DNS tunneling only for command and control (C2) and virtual private network (VPN) purposes.
Malicious actors occasionally employ DNS tunneling as a covert communications channel, because it can bypass conventional network firewalls. This allows C2 traffic and data exfiltration that can remain hidden from some traditional detection methods.
However, we recently detected three recent campaigns using DNS tunneling for purposes outside of traditional C2 and VPN use: scanning and tracking. In scanning, adversaries employ DNS tunneling to scan a victim's network infrastructure and gather information useful for future attack
Unit42
Leveraging DNS Tunneling for Tracking and Scanning
blogs_unit42·2024-05-13
Leveraging DNS Tunneling for Tracking and Scanning
Threat Research Center
Threat Research
DNS
## Leveraging DNS Tunneling for Tracking and Scanning
Shu Wang
Daiping Liu
Ruian Duan
Published: May 13, 2024
DNS
Learning Hub
Threat Research
DNS tunneling
Scanning
Tracking
## Executive Summary
This article presents a case study on new applications of domain name system (DNS) tunneling we have found in the wild. These techniques expand beyond DNS tunneling only for command and control (C2) and virtual private network (VPN) purposes.
Malicious actors occasionally employ DNS tunneling as a covert communications channel, because it can bypass conventional network firewalls. This allows C2 traffic and data exfiltration that can remain hidden from some traditional detection methods.
However, we recently detected three recent camp
Bugzilla
CVE-2012-1033 bind: deleted domain name resolving flaw
bugzilla·2012-02-08·CVSS 5.0
CVE-2012-1033 [MEDIUM] CVE-2012-1033 bind: deleted domain name resolving flaw
CVE-2012-1033 bind: deleted domain name resolving flaw
A vulnerability was found that affects the large majority of popular DNS implementations which allow a malicious domain name to stay resolvable long after it has been removed from the upper level servers, including ISC BIND. According to Tsinghua University researchers, it exploits a flaw in DNS cache update policy, which prevents effective domain name revocation.
There is currently no known exploit, and no fix has been produced by ISC as of yet.
External References:
https://www.isc.org/software/bind/advisories/cve-2012-1033
Discussion:
ISC has updated their CVE page to note that they do not intend to fix this as it is an issue at the DNS protocol level, and not in the implementation. They do intend to do further analysis and res
http://marc.info/?l=bugtraq&m=135638082529878&w=2http://osvdb.org/78916http://rhn.redhat.com/errata/RHSA-2012-0717.htmlhttp://secunia.com/advisories/47884http://www.kb.cert.org/vuls/id/542123http://www.securityfocus.com/bid/51898http://www.securitytracker.com/id?1026647https://exchange.xforce.ibmcloud.com/vulnerabilities/73053https://hermes.opensuse.org/messages/15136456https://hermes.opensuse.org/messages/15136477https://www.isc.org/software/bind/advisories/cve-2012-1033http://marc.info/?l=bugtraq&m=135638082529878&w=2http://osvdb.org/78916http://rhn.redhat.com/errata/RHSA-2012-0717.htmlhttp://secunia.com/advisories/47884http://www.kb.cert.org/vuls/id/542123http://www.securityfocus.com/bid/51898http://www.securitytracker.com/id?1026647https://exchange.xforce.ibmcloud.com/vulnerabilities/73053https://hermes.opensuse.org/messages/15136456https://hermes.opensuse.org/messages/15136477https://www.isc.org/software/bind/advisories/cve-2012-1033
2012-02-08
Published