CVE-2012-4244
published 2012-09-14CVE-2012-4244: ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a…
PriorityP345high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
36.80%
98.3th percentile
ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.4.dfsg-1 (bookworm) | bind9 1:9.8.4.dfsg-1 (bookworm) |
| debian | isc-dhcp | < bind9 1:9.8.4.dfsg-1 (bookworm) | bind9 1:9.8.4.dfsg-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by a DNS query for a resource record whose RDATA exceeds 65535 bytes, causing an assertion failure and named daemon exit. Monitor for unusually large DNS resource record responses (RDATA > 65535 bytes) in DNS traffic. ↗
- →Attack vector is remote: an attacker can cause a recursive resolver to crash by directing it to query an authoritative server serving an oversized resource record. Detect recursive resolvers querying authoritative servers that return abnormally large RDATA in a single resource record. ↗
- →Authoritative servers are also at risk if a zone file containing an oversized resource record is loaded from disk or via zone transfer. Monitor zone transfer (AXFR/IXFR) traffic for records with RDATA exceeding 65535 bytes. ↗
- →The crash manifests as a REQUIRE exception (assertion failure) in the named process. Monitor system logs for named process exits with assertion/REQUIRE failure messages. ↗
- ·Affected BIND versions are 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3. Ensure named version is patched to at least these fix versions. ↗
- ·No workaround is available for this vulnerability; the only mitigation is patching or disabling the BIND name server entirely. ↗
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vSphere security updates for the authentication service and third party libraries
vendor_vmware·2013-01-31·CVSS 10.0
CVE-2011-1202 [CRITICAL] VMware vSphere security updates for the authentication service and third party libraries
VMSA-2013-0001: VMware vSphere security updates for the authentication service and third party libraries
a. VMware vSphere client-side authentication memory corruption vulnerability VMware vCenter Server, vSphere Client, and ESX contain a vulnerability in the handling of the management authentication protocol. To exploit this vulnerability, an attacker must convince either vCenter Server, vSphere Client or ESX to interact with a malicious server as a client. Exploitation of the issue may lead to code execution on the client system. To reduce the likelihood of exploitation, vSphere components should be deployed on an isolated management network. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2013-1405 to this issue. Column 4 of the following tabl
VMware
VMware security updates for vCSA, vCenter Server, and ESXi
vendor_vmware·2012-12-20·CVSS 4.0
CVE-2009-5029 [MEDIUM] VMware security updates for vCSA, vCenter Server, and ESXi
VMSA-2012-0018: VMware security updates for vCSA, vCenter Server, and ESXi
a. vCenter Server Appliance directory traversal The vCenter Server Appliance (vCSA) contains a directory traversal vulnerability that allows an authenticated remote user to retrieve arbitrary files. Exploitation of this issue may expose sensitive information stored on the server. VMware would like to thank Alexander Minozhenko from ERPScan for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-6324 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product vCSA Product Vers
BSD
FreeBSD-SA-12:06.bind: Multiple Denial of Service vulnerabilities with named(8)
bsd_advisories·2012-11-22·CVSS 7.8
CVE-2012-4244 [HIGH] FreeBSD-SA-12:06.bind: Multiple Denial of Service vulnerabilities with named(8)
FreeBSD-SA-12:06.bind Security Advisory
The FreeBSD Project
Topic: Multiple Denial of Service vulnerabilities with named(8)
Category: contrib
Module: bind
Announced: 2012-11-22
Affects: All supported versions of FreeBSD before 9.1-RC2.
Corrected: 2012-11-22 23:15:38 UTC (RELENG_7, 7.4-STABLE)
2012-11-22 22:52:15 UTC (RELENG_7_4, 7.4-RELEASE-p11)
2012-10-11 13:25:09 UTC (RELENG_8, 8.3-STABLE)
2012-11-22 22:52:15 UTC (RELENG_8_3, 8.3-RELEASE-p5)
2012-10-10 19:50:15 UTC (RELENG_9, 9.1-PRERELEASE)
2012-11-22 22:52:15 UTC (RELENG_9_0, 9.0-RELEASE-p5)
2012-11-22 22:52:15 UTC (RELENG_9_1, 9.1-RC1-p1)
2012-11-22 22:52:15 UTC (RELENG_9_1, 9.1-RC2-p1)
2012-11-22 22:52:15 UTC (RELENG_9_1, 9.1-RC3-p1)
CVE Name: CVE-2012-4244, CVE-2012-5166
For general information regarding FreeBSD Security Advisori
Ubuntu
Bind vulnerability
vendor_ubuntu·2012-09-13
CVE-2012-4244 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash or if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled certain specially crafted
long resource records. A remote attacker could use this flaw to cause Bind
to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: specially crafted resource record causes named to exit
vendor_redhat·2012-09-12·CVSS 7.8
CVE-2012-4244 [HIGH] bind: specially crafted resource record causes named to exit
bind: specially crafted resource record causes named to exit
ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.
Debian
CVE-2012-4244: bind9 - ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and ...
vendor_debian·2012·CVSS 7.8
CVE-2012-4244 [HIGH] CVE-2012-4244: bind9 - ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and ...
ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.
Scope: local
bookworm: resolved (fixed in 1:9.8.4.dfsg-1)
bullseye: resolved (fixed in 1:9.8.4.dfsg-1)
forky: resolved (fixed in 1:9.8.4.dfsg-1)
sid: resolved (fixed in 1:9.8.4.dfsg-1)
trixie: resolved (fixed in 1:9.8.4.dfsg-1)
GHSA
GHSA-hrmx-gwc2-vh68: ISC BIND 9
ghsa_unreviewed·2022-05-17
CVE-2012-4244 [HIGH] GHSA-hrmx-gwc2-vh68: ISC BIND 9
ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.
OSV
CVE-2012-4244: ISC BIND 9
osv·2012-09-14·CVSS 7.8
CVE-2012-4244 [HIGH] CVE-2012-4244: ISC BIND 9
ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4244 bind: specially crafted resource record causes named to exit [fedora-all]
bugzilla·2012-09-12·CVSS 7.8
CVE-2012-4244 [HIGH] CVE-2012-4244 bind: specially crafted resource record causes named to exit [fedora-all]
CVE-2012-4244 bind: specially crafted resource record causes named to exit [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?ty
Bugzilla
CVE-2012-4244 bind: specially crafted resource record causes named to exit
bugzilla·2012-09-12·CVSS 7.8
CVE-2012-4244 [HIGH] CVE-2012-4244 bind: specially crafted resource record causes named to exit
CVE-2012-4244 bind: specially crafted resource record causes named to exit
A flaw in ISC BIND was reported [1] where a nameserver could be caused to exit with a REQUIRE exception if it received a specially crafted resource record with RDATA that exceeded 65535 bytes and then received a subsequent query for that record. This can be exploited remotely against recursive servers by getting them to query for records provided by an authoritative server. It also affects authoritative servers if a zone containing this kind of resource record is loaded from a file on disk or via a zone transfer.
[1] https://kb.isc.org/article/AA-00778/74
Discussion:
Created attachment 612201
diff of bind-9.6-ESV-R7-P2 to P3
--- 9.6-ESV-R7-P3 released ---
3364. [security] Named could die on specially crafted r
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/087697.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/087703.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/088381.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00007.htmlhttp://marc.info/?l=bugtraq&m=141879471518471&w=2http://rhn.redhat.com/errata/RHSA-2012-1266.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1267.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1268.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1365.htmlhttp://secunia.com/advisories/50560http://secunia.com/advisories/50579http://secunia.com/advisories/50582http://secunia.com/advisories/50645http://secunia.com/advisories/50673http://secunia.com/advisories/51096http://support.apple.com/kb/HT5880http://www.debian.org/security/2012/dsa-2547http://www.mandriva.com/security/advisories?name=MDVSA-2012:152http://www.securityfocus.com/bid/55522http://www.ubuntu.com/usn/USN-1566-1https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://kb.isc.org/article/AA-00778https://security.netapp.com/advisory/ntap-20221209-0008/http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/087697.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/087703.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/088381.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00007.htmlhttp://marc.info/?l=bugtraq&m=141879471518471&w=2http://rhn.redhat.com/errata/RHSA-2012-1266.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1267.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1268.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1365.htmlhttp://secunia.com/advisories/50560http://secunia.com/advisories/50579http://secunia.com/advisories/50582http://secunia.com/advisories/50645http://secunia.com/advisories/50673http://secunia.com/advisories/51096http://support.apple.com/kb/HT5880http://www.debian.org/security/2012/dsa-2547http://www.mandriva.com/security/advisories?name=MDVSA-2012:152http://www.securityfocus.com/bid/55522http://www.ubuntu.com/usn/USN-1566-1https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://kb.isc.org/article/AA-00778https://security.netapp.com/advisory/ntap-20221209-0008/
2012-09-14
Published