CVE-2012-5689
published 2013-01-25CVE-2012-5689: ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite…
PriorityP432high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
12.04%
95.7th percentile
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.8.4.dfsg.P1-6+nmu1 (bookworm) | bind9 1:9.8.4.dfsg.P1-6+nmu1 (bookworm) |
| debian | isc-dhcp | < bind9 1:9.8.4.dfsg.P1-6+nmu1 (bookworm) | bind9 1:9.8.4.dfsg.P1-6+nmu1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.8.4.dfsg.P1-6+nmu1 | 1:9.8.4.dfsg.P1-6+nmu1 |
| isc | bind9 | >= 0 < 1:9.8.4.dfsg.P1-6+nmu1 | 1:9.8.4.dfsg.P1-6+nmu1 |
| isc | bind9 | >= 0 < 1:9.8.4.dfsg.P1-6+nmu1 | 1:9.8.4.dfsg.P1-6+nmu1 |
| isc | bind9 | >= 0 < 1:9.8.4.dfsg.P1-6+nmu1 | 1:9.8.4.dfsg.P1-6+nmu1 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.4 | 1:9.9.5.dfsg-3ubuntu0.4 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9253-pf7v-j2vx: ISC BIND 9
ghsa_unreviewed·2022-05-17
CVE-2012-5689 [HIGH] CWE-20 GHSA-9253-pf7v-j2vx: ISC BIND 9
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
OSV
bind9 vulnerabilities
osv·2015-07-28·CVSS 7.1
CVE-2015-5477 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Jonathan Foote discovered that Bind incorrectly handled certain TKEY
queries. A remote attacker could use this issue with a specially crafted
packet to cause Bind to crash, resulting in a denial of service.
(CVE-2015-5477)
Pories Ediansyah discovered that Bind incorrectly handled certain
configurations involving DNS64. A remote attacker could use this issue with
a specially crafted query to cause Bind to crash, resulting in a denial of
service. This issue only affected Ubuntu 12.04 LTS. (CVE-2012-5689)
OSV
CVE-2012-5689: ISC BIND 9
osv·2013-01-25·CVSS 7.1
CVE-2012-5689 [HIGH] CVE-2012-5689: ISC BIND 9
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2015-07-28·CVSS 7.1
CVE-2012-5689 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Jonathan Foote discovered that Bind incorrectly handled certain TKEY
queries. A remote attacker could use this issue with a specially crafted
packet to cause Bind to crash, resulting in a denial of service.
(CVE-2015-5477)
Pories Ediansyah discovered that Bind incorrectly handled certain
configurations involving DNS64. A remote attacker could use this issue with
a specially crafted query to cause Bind to crash, resulting in a denial of
service. This issue only affected Ubuntu 12.04 LTS. (CVE-2012-5689)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: denial of service when processing queries and with both DNS64 and RPZ enabled
vendor_redhat·2013-01-24·CVSS 7.1
CVE-2012-5689 [HIGH] bind: denial of service when processing queries and with both DNS64 and RPZ enabled
bind: denial of service when processing queries and with both DNS64 and RPZ enabled
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
Statement: This issue did not affect the versions of bind or bind97 packages as shipped with Red Hat Enterprise Linux 4 and 5.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-5689: bind9 - ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configura...
vendor_debian·2012·CVSS 7.1
CVE-2012-5689 [HIGH] CVE-2012-5689: bind9 - ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configura...
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
Scope: local
bookworm: resolved (fixed in 1:9.8.4.dfsg.P1-6+nmu1)
bullseye: resolved (fixed in 1:9.8.4.dfsg.P1-6+nmu1)
forky: resolved (fixed in 1:9.8.4.dfsg.P1-6+nmu1)
sid: resolved (fixed in 1:9.8.4.dfsg.P1-6+nmu1)
trixie: resolved (fixed in 1:9.8.4.dfsg.P1-6+nmu1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5689 bind: denial of service when processing queries and with both DNS64 and RPZ enabled [fedora-all]
bugzilla·2013-01-24·CVSS 7.1
CVE-2012-5689 [HIGH] CVE-2012-5689 bind: denial of service when processing queries and with both DNS64 and RPZ enabled [fedora-all]
CVE-2012-5689 bind: denial of service when processing queries and with both DNS64 and RPZ enabled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availa
Bugzilla
CVE-2012-5689 bind: denial of service when processing queries and with both DNS64 and RPZ enabled
bugzilla·2013-01-23·CVSS 7.1
CVE-2012-5689 [HIGH] CVE-2012-5689 bind: denial of service when processing queries and with both DNS64 and RPZ enabled
CVE-2012-5689 bind: denial of service when processing queries and with both DNS64 and RPZ enabled
An error condition may occur when a nameserver which is configured to use DNS64 performs a AAAA lookup for a record with an A record rewrite rule in a Response Policy Zone (RPZ.) If the RPZ is unable to provide a AAAA record for the name, but does provide a rewritten A record, then the DNS64 processing code will attempt to remap that A record into a AAAA record. Due to a coding error, this interaction between the RPZ database and the DNS64 remapping code can cause the named process to terminate with an assertion failure.
This only affects BIND 9.8.0 through to 9.8.4-P1 and 9.9.0 through to 9.9.2-P1. It also requires the server to be using RPZ rewrite rules (specifically, A rewrite rules but
http://rhn.redhat.com/errata/RHSA-2013-0550.htmlhttp://www.isc.org/software/bind/advisories/cve-2012-5689http://www.ubuntu.com/usn/USN-2693-1https://kb.isc.org/article/AA-00855/http://rhn.redhat.com/errata/RHSA-2013-0550.htmlhttp://www.isc.org/software/bind/advisories/cve-2012-5689http://www.ubuntu.com/usn/USN-2693-1https://kb.isc.org/article/AA-00855/
2013-01-25
Published