CVE-2016-9131
published 2017-01-12CVE-2016-9131: named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
40.56%
98.5th percentile
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-11 (bookworm) | bind9 1:9.10.3.dfsg.P4-11 (bookworm) |
| debian | debian_linux | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.0 – 9.9.8 | — |
| isc | bind | 9.10.0 – 9.10.3 | — |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.11 | 1:9.9.5.dfsg-3ubuntu0.11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.4 | 1:9.10.3.dfsg.P4-8ubuntu1.4 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect DNS ANY query responses containing a TKEY record (type 249) with rdclass 0xff — this mismatch triggers the assertion failure in BIND's Resolver.c cache_name() / dns_db_addrdataset() ↗
- →Target: BIND recursive servers only — the malformed TKEY response must be received by a recursive server that issued an ANY query; authoritative-only servers are not directly at risk ↗
- →No authentication is required to exploit this vulnerability — any remote attacker who can influence DNS responses seen by the recursive resolver can trigger the crash ↗
- →Use Fortinet IPS signature ISC.BIND.TKEY.Query.Reponse.Handling.DoS for network-level detection of exploit attempts ↗
- ·Affected versions: ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9131)
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9147)
It was discovered that Bind incorrectly handled certain malformed DS record
responses. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444
Red Hat
bind: assertion failure while processing response to an ANY query
vendor_redhat·2017-01-11·CVSS 7.5
CVE-2016-9131 [HIGH] bind: assertion failure while processing response to an ANY query
bind: assertion failure while processing response to an ANY query
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
A denial of service flaw was found in the way BIND processed a response to an ANY query. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-9131: bind9 - named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x befor...
vendor_debian·2016·CVSS 7.5
CVE-2016-9131 [HIGH] CVE-2016-9131: bind9 - named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x befor...
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-11)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-11)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-11)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-11)
trixie: resolved (fixed in 1:9.10.3.dfsg.P4-11)
GHSA
GHSA-75r9-9rpr-7px8: named in ISC BIND 9
ghsa_unreviewed·2022-05-13
CVE-2016-9131 [HIGH] CWE-20 GHSA-75r9-9rpr-7px8: named in ISC BIND 9
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
OSV
CVE-2016-9131: named in ISC BIND 9
osv·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] CVE-2016-9131: named in ISC BIND 9
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
OSV
bind9 vulnerabilities
osv·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9131)
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9147)
It was discovered that Bind incorrectly handled certain malformed DS record
responses. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9131 bind: assertion failure while processing response to an ANY query [fedora-all]
bugzilla·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] CVE-2016-9131 bind: assertion failure while processing response to an ANY query [fedora-all]
CVE-2016-9131 bind: assertion failure while processing response to an ANY query [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2016-9131 bind99: bind: assertion failure while processing response to an ANY query [fedora-all]
bugzilla·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] CVE-2016-9131 bind99: bind: assertion failure while processing response to an ANY query [fedora-all]
CVE-2016-9131 bind99: bind: assertion failure while processing response to an ANY query [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-9131 bind: assertion failure while processing response to an ANY query
bugzilla·2017-01-09·CVSS 7.5
CVE-2016-9131 [HIGH] CVE-2016-9131 bind: assertion failure while processing response to an ANY query
CVE-2016-9131 bind: assertion failure while processing response to an ANY query
A malformed query response received by a recursive server in response to a query of RTYPE ANY could trigger an assertion failure while named is attempting to add the RRs in the query response to the cache. While the combination of properties which triggers the assertion should not occur in normal traffic, it is potentially possible for the assertion to be triggered deliberately by an attacker sending a specially-constructed answer having the required properties, after having engineered a scenario whereby an ANY query is sent to the recursive server for the target QNAME. A recursive server will itself only send a query of type ANY if it receives a client query of type ANY for a QNAME for which it has no RRsets
Fortinet
The Analysis of ISC BIND Response Authority Section RRSIG Missing DoS (CVE-2016-9444)
blogs_fortinet·2017-02-06·CVSS 7.5
CVE-2016-9444 [HIGH] The Analysis of ISC BIND Response Authority Section RRSIG Missing DoS (CVE-2016-9444)
FORTIGUARD LABS THREAT RESEARCH
The Analysis of ISC BIND Response Authority Section RRSIG Missing DoS (CVE-2016-9444)
By Dehui Yin | February 06, 2017
Domain Name System Security Extensions (DNSSEC) secures the Domain Name System (DNS), right?
Yes, but that’s not the whole story. DNSSEC can also introduce troubles into your DNS server.
Recently, a BIND bug caused by a missing RRSIG record, which is a part of DNSSEC, was fixed by a patch from the Internet Systems Consortium (ISC). This bug affects all versions of BIND recursive servers, and can cause a denial of service (DoS.)
This potential DoS vulnerability is caused by a RUNTIME CHECK error in Resolver.c when handling the DNS query response AUTHORITY section without covering RRSIG. In this post we will examine the BIND source codes
Fortinet
Analysis of ISC BIND TKEY Query Response Handling DoS (CVE-2016-9131)
blogs_fortinet·2017-01-18·CVSS 7.5
CVE-2016-9131 [HIGH] Analysis of ISC BIND TKEY Query Response Handling DoS (CVE-2016-9131)
FORTIGUARD LABS THREAT RESEARCH
Analysis of ISC BIND TKEY Query Response Handling DoS (CVE-2016-9131)
By Dehui Yin | January 18, 2017
Another TKEY record-related bug in BIND has been fixed with a patch from the Internet Systems Consortium (ISC) that was released just after the New Year. This bug may take down BIND recursive servers by sending a simple query response with TKEY record, thereby causing a denial of service (DoS).
This potential DoS vulnerability is caused by an assertion failure in Resolver.c when caching the DNS response with TKEY Record. In this post we will analyze the BIND source codes and expose the root cause of this vulnerability.
The TKEY record (record type 249) is used to operate the secret keys information shared between DNS resolvers and servers. It is not supp
Fortinet
Analysis of ISC BIND DNAME Answer Handling DoS (CVE-2016-8864)
blogs_fortinet·2016-11-08·CVSS 7.5
CVE-2016-8864 [HIGH] Analysis of ISC BIND DNAME Answer Handling DoS (CVE-2016-8864)
FORTIGUARD LABS THREAT RESEARCH
Analysis of ISC BIND DNAME Answer Handling DoS (CVE-2016-8864)
By Dehui Yin | November 08, 2016
Adefect in BIND's handling of a DNAME answer was fixed in a critical update from the Internet Systems Consortium (ISC) several days ago. This defect affects all BIND recursive servers, and can be exploited to remotely take down recursive servers by sending a simple DNAME answer thereby causing a denial of service (DoS.)
This potential DoS vulnerability is caused by an assertion failure in Resolver.c or Db.c when caching the DNS response with DNAME Record. In this post we will examine the underlying code and expose the root cause of this vulnerability.
The DNAME record is used to redirect a DNS name to another domain. It has the following format:
DNAME
The DN
Fortinet
Internet In Danger: Analysis of ISC Bind Patch (part 2)
blogs_fortinet·2016-04-01·CVSS 8.6
CVE-2016-1286 [HIGH] Internet In Danger: Analysis of ISC Bind Patch (part 2)
FORTIGUARD LABS THREAT RESEARCH
Internet In Danger: Analysis of ISC Bind Patch (part 2)
By Amir Zali | April 01, 2016
In this second part article, we analyze two recent vulnerabilities in ISC BIND identified as CVE-2016-1286 and CVE-2016-2088. Based on advisories, these bugs can be triggered using a malformed DNAME record (CVE-2016-1286) or an OPT COOKIE records (CVE-2016-2088).
These two bugs share the same attack scenario that can only be triggered when a BIND server makes a request and then receives a malformed response. Based on this requirement, recursive servers are at highest risk to this attack, because it’s not straightforward to ask an authoritative-only server to make a DNS request.
CVE-2016-1286[1]
Named is a service daemon and part of the BIND application package. Named t
Fortinet
Internet In Danger: Analysis of ISC Bind Patch (part 1)
blogs_fortinet·2016-03-29·CVSS 6.8
[MEDIUM] Internet In Danger: Analysis of ISC Bind Patch (part 1)
FORTIGUARD LABS THREAT RESEARCH
Internet In Danger: Analysis of ISC Bind Patch (part 1)
By Dehui Yin | March 29, 2016
The Internet Systems Consortium just released a couple of days ago a new patch (version 9.10.3-P4) to fix some issues in the most popular DNS server software in the world.
The release note is available at https://kb.isc.org/article/AA-01363/81/BIND-9.10.3-P4-Release-Notes.html
In this series of two articles, we will detail our investigation of these vulnerabilities and how we were able to protect our customers by deploying widely our detection.
ISC released a patch for the BIND rndc control channel DoS vulnerability (CVE-2016-1285). According to ISC, this vulnerability is due to an assertion failure in the application called named when it’s handling a malformed packet
http://rhn.redhat.com/errata/RHSA-2017-0062.htmlhttp://www.debian.org/security/2017/dsa-3758http://www.securityfocus.com/bid/95386http://www.securitytracker.com/id/1037582https://access.redhat.com/errata/RHSA-2017:1583https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05381687https://kb.isc.org/article/AA-01439/74/CVE-2016-9131https://security.gentoo.org/glsa/201708-01https://security.netapp.com/advisory/ntap-20180926-0005/http://rhn.redhat.com/errata/RHSA-2017-0062.htmlhttp://www.debian.org/security/2017/dsa-3758http://www.securityfocus.com/bid/95386http://www.securitytracker.com/id/1037582https://access.redhat.com/errata/RHSA-2017:1583https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05381687https://kb.isc.org/article/AA-01439/74/CVE-2016-9131https://security.gentoo.org/glsa/201708-01https://security.netapp.com/advisory/ntap-20180926-0005/
2017-01-12
Published