ISC BIND < 4.9.11 stub resolver (libresolv.a) DNS Response Overflow

critical Nessus Plugin ID 11857

Language:

Synopsis

It is possible to use the remote name server to execute arbitrary code on the remote host.

Description

The remote BIND 4.x server, according to its version number, is vulnerable to a buffer overflow in the DNS stub resolver library.

An attacker might use this flaw to execute arbitrary code on the remote host.

Solution

Upgrade to 4.9.11 or later in the 4.x branch, or consider upgrading to a more recent release.

Plugin Details

Severity: Critical

ID: 11857

File Name: bind_stub_res.nasl

Version: 1.24

Type: remote

Family: DNS

Published: 9/29/2003

Updated: 9/21/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:isc:bind

Required KB Items: bind/version

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 11/12/2002

Reference Information

CVE: CVE-2002-0029

BID: 6186

IAVA: 2023-A-0320-S