CVE-2012-1667
published 2012-06-05CVE-2012-1667: ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource…
PriorityP348high8.5CVSS 2.0
AVNACLAuNCPINAC
EPSS
13.41%
96.0th percentile
ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.1.dfsg.P1-4.1 (bookworm) | bind9 1:9.8.1.dfsg.P1-4.1 (bookworm) |
| debian | isc-dhcp | < bind9 1:9.8.1.dfsg.P1-4.1 (bookworm) | bind9 1:9.8.1.dfsg.P1-4.1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target process is named(8) (ISC BIND DNS daemon); look for unexpected termination or crash of the named process following receipt of crafted DNS resource records with zero-length RDATA fields. ↗
- →Monitor named for memory disclosure to DNS clients — resolving servers may leak portions of process memory in responses when processing zero-length RDATA records. ↗
- →Authoritative servers are at risk of crash on zone transfer restart; monitor for named crashes following AXFR/IXFR zone transfers that may have introduced zero-length RDATA records. ↗
- →This vulnerability primarily affects recursive resolvers; prioritize monitoring of recursive BIND instances for anomalous crashes or unexpected data in DNS responses. ↗
- →The flaw may also result in zone data corruption in certain configurations; monitor zone files and zone transfer logs for data integrity anomalies. ↗
- ·No workaround is available for this vulnerability; the only mitigation is patching to a fixed BIND version (9.6-ESV-R7-P1, 9.7.6-P1, 9.8.3-P1, or 9.9.1-P1). Systems not running BIND named are unaffected. ↗
- ·All supported BIND 9.x branches are affected: 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV / 9.6-ESV before 9.6-ESV-R7-P1. ↗
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:L/Au:N/C:P/I:N/A:C
osv8.5HIGH
vendor_debian8.5HIGH
vendor_redhat8.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware security updates for vSphere API and ESX Service Console
vendor_vmware·2012-11-15·CVSS 5.0
CVE-2011-4940 [MEDIUM] VMware security updates for vSphere API and ESX Service Console
VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
a. VMware vSphere API denial of service vulnerability The VMware vSphere API contains a denial of service vulnerability. This issue allows an unauthenticated user to send a maliciously crafted API request and disable the host daemon. Exploitation of the issue would prevent management activities on the host but any virtual machines running on the host would be unaffected. VMware would like to thank Sebastián Tello of Core Security Technologies for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-5703 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is a
BSD
FreeBSD-SA-12:03.bind: Incorrect handling of zero-length RDATA fields in named(8)
bsd_advisories·2012-06-12·CVSS 8.5
CVE-2012-1667 [HIGH] FreeBSD-SA-12:03.bind: Incorrect handling of zero-length RDATA fields in named(8)
FreeBSD-SA-12:03.bind Security Advisory
The FreeBSD Project
Topic: Incorrect handling of zero-length RDATA fields in named(8)
Category: contrib
Module: bind
Announced: 2012-06-12
Credits: Dan Luther, Jeffrey A. Spain
Affects: All supported versions of FreeBSD
Corrected: 2012-06-12 12:10:10 UTC (RELENG_7, 7.4-STABLE)
2012-06-12 12:10:10 UTC (RELENG_7_4, 7.4-RELEASE-p9)
2012-06-04 22:21:55 UTC (RELENG_8, 8.3-STABLE)
2012-06-12 12:10:10 UTC (RELENG_8_3, 8.3-RELEASE-p3)
2012-06-12 12:10:10 UTC (RELENG_8_2, 8.2-RELEASE-p9)
2012-06-12 12:10:10 UTC (RELENG_8_1, 8.1-RELEASE-p11)
2012-06-04 22:14:33 UTC (RELENG_9, 9.0-STABLE)
2012-06-12 12:10:10 UTC (RELENG_9_0, 9.0-RELEASE-p3)
CVE Name: CVE-2012-1667
For general information regarding FreeBSD Security Advisories,
including descriptions of the fi
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2012-06-05·CVSS 5.0
CVE-2012-1033 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Dan Luther discovered that Bind incorrectly handled zero length rdata
fields. A remote attacker could use this flaw to cause Bind to crash or
behave erratically, resulting in a denial of service. (CVE-2012-1667)
It was discovered that Bind incorrectly handled revoked domain names. A
remote attacker could use this flaw to cause malicious domain names to be
continuously resolvable even after they have been revoked. (CVE-2012-1033)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: handling of zero length rdata can cause named to terminate unexpectedly
vendor_redhat·2012-06-04·CVSS 8.5
CVE-2012-1667 [HIGH] bind: handling of zero length rdata can cause named to terminate unexpectedly
bind: handling of zero length rdata can cause named to terminate unexpectedly
ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.
Debian
CVE-2012-1667: bind9 - ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and ...
vendor_debian·2012·CVSS 8.5
CVE-2012-1667 [HIGH] CVE-2012-1667: bind9 - ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and ...
ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
forky: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
sid: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
trixie: resolved (fixed in 1:9.8.1.dfsg.P1-4.1)
GHSA
GHSA-8wqw-72q7-h4q9: ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2012-1667 [HIGH] GHSA-8wqw-72q7-h4q9: ISC BIND 9
ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.
OSV
CVE-2012-1667: ISC BIND 9
osv·2012-06-05·CVSS 8.5
CVE-2012-1667 [HIGH] CVE-2012-1667: ISC BIND 9
ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1667 bind: handling of zero length rdata can cause named to terminate unexpectedly [fedora-all]
bugzilla·2012-06-04·CVSS 8.5
CVE-2012-1667 [HIGH] CVE-2012-1667 bind: handling of zero length rdata can cause named to terminate unexpectedly [fedora-all]
CVE-2012-1667 bind: handling of zero length rdata can cause named to terminate unexpectedly [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.or
Bugzilla
CVE-2012-1667 bind: handling of zero length rdata can cause named to terminate unexpectedly
bugzilla·2012-06-04·CVSS 8.5
CVE-2012-1667 [HIGH] CVE-2012-1667 bind: handling of zero length rdata can cause named to terminate unexpectedly
CVE-2012-1667 bind: handling of zero length rdata can cause named to terminate unexpectedly
ISC has sent a brief notification about a flaw affecting bind 9 versions to be disclosed on Jun 4. CVE-2012-1667 was assigned to this issue, but there are no other details currently available about this flaw.
Discussion:
Public now via upstream advisory. The flaw is in the handling of the zero length rdata records, which may trigger named crash, memory disclosure, or zone data corruption in certain configurations. This primarily affects recursive resolvers.
Issue was fixed in upstream versions:
9.6-ESV-R7-P1, 9.7.6-P1, 9.8.3-P1, and 9.9.1-P1
External Reference:
http://www.isc.org/software/bind/advisories/cve-2012-1667
---
Created bind tracking bugs for this issue
Affects: fedora-all [bug 82
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00010.htmlhttp://marc.info/?l=bugtraq&m=134132772016230&w=2http://rhn.redhat.com/errata/RHSA-2012-0717.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1110.htmlhttp://secunia.com/advisories/51096http://support.apple.com/kb/HT5501http://www.debian.org/security/2012/dsa-2486http://www.isc.org/software/bind/advisories/cve-2012-1667http://www.kb.cert.org/vuls/id/381699http://www.mandriva.com/security/advisories?name=MDVSA-2012:089http://www.securityfocus.com/bid/53772http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://kb.isc.org/article/AA-00698http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00010.htmlhttp://marc.info/?l=bugtraq&m=134132772016230&w=2http://rhn.redhat.com/errata/RHSA-2012-0717.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1110.htmlhttp://secunia.com/advisories/51096http://support.apple.com/kb/HT5501http://www.debian.org/security/2012/dsa-2486http://www.isc.org/software/bind/advisories/cve-2012-1667http://www.kb.cert.org/vuls/id/381699http://www.mandriva.com/security/advisories?name=MDVSA-2012:089http://www.securityfocus.com/bid/53772http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://kb.isc.org/article/AA-00698
2012-06-05
Published