Multiple Vulnerabilities in BIND

Multiple vulnerabilities have been discoverd in BIND 4 and BIND 8.

Steve Manzuik

January 28, 2001

1 Min Read
ITPro Today logo

Reported January 29, 2001, by CERT.

VERSIONS AFFECTED

DESCRIPTIONMultiple vulnerabilities have been discovered in Internet Software Consortium (ISC) BIND versions 4 and 8. In the first vulnerability, in BIND 8, a remote buffer overflow can let an attacker execute arbitrary code without having control over a DNS server. The second vulnerability, in BIND 4, is also a buffer overflow that requires the attacker to have control over a DNS server to execute arbitrary code. In the third vulnerability, also in BIND 4, an attacker can use a format string issue to launch arbitrary commands.

VENDOR RESPONSE

ISC is aware of these issues and has released patches. BIND 4.9.8 and 8.2.3 address the vulnerabilities.

CREDITDiscovered by Covert Labs.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like