ISC BIND 9 < 9.9.9-P5 / 9.9.9-S7 / 9.10.4-P5 / 9.11.0-P2 Multiple DoS

Medium Nessus Plugin ID 96625

Synopsis

The remote name server is affected by multiple denial of service
vulnerabilities.

Description

According to its self-reported version number, the instance of ISC
BIND 9 running on the remote name server is 9.9.x prior to 9.9.9-P5 or
9.9.9-S7, 9.10.x prior to 9.10.4-P5, or 9.11.x prior to 9.11.0-P2. It
is, therefore, affected by multiple denial of service
vulnerabilities :

- A denial of service vulnerability exists in named due to
a flaw that is triggered during the handling of a
specially crafted answer packet in a response to an
RTYPE ANY query. An unauthenticated, remote attacker can
exploit this to cause an assertion failure and daemon
exit. Note that this vulnerability affects versions
9.4.0 to 9.6-ESV-R11-W1, 9.8.5 to 9.8.8, 9.9.3 to
9.9.9-P4, 9.9.9-S1 to 9.9.9-S6, 9.10.0 to 9.10.4-P4, and
9.11.0 to 9.11.0-P1. (CVE-2016-9131)

- A denial of service vulnerability exists in named in
DNSSEC-enabled authoritative servers that is triggered
during the handling of a query response that contains
inconsistent DNSSEC information. An unauthenticated,
remote attacker can exploit this to cause an assertion
failure and daemon exit. Note that this vulnerability
affects versions 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and
9.11.0-P1. (CVE-2016-9147)

- A denial of service vulnerability exists in named due to
a flaw that is triggered during the handling of a
specially crafted answer that contains a DS resource
record. An unauthenticated, remote attacker can exploit
this to cause an assertion failure and daemon exit. Note
that this vulnerability affects versions 9.6-ESV-R9 to
9.6-ESV-R11-W1, 9.8.5 to 9.8.8, 9.9.3 to 9.9.9-P4,
9.9.9-S1 to 9.9.9-S6, 9.10.0 to 9.10.4-P4, and 9.11.0 to
9.11.0-P1. (CVE-2016-9444)

- A denial of service vulnerability exists in named in the
nxdomain-redirect functionality that is triggered when
handling a specially crafted query. An unauthenticated,
remote attacker can exploit this to cause a REQUIRE
assertion failure and daemon exit. Note that this
vulnerability affects versions 9.9.8-S1 to 9.9.8-S3,
9.9.9-S1 to 9.9.9-S6, and 9.11.0-9.11.0 to P1.
(CVE-2016-9778)

Note that Nessus has not tested for these issues but has instead
relied only on the application's self-reported version number.

Solution

Upgrade to ISC BIND version 9.9.9-P5 / 9.9.9-S7 / 9.10.4-P5 /
9.11.0-P2 or later.

See Also

https://kb.isc.org/article/AA-01439

https://kb.isc.org/article/AA-01440

https://kb.isc.org/article/AA-01441

https://kb.isc.org/docs/aa-01442

Plugin Details

Severity: Medium

ID: 96625

File Name: bind9_CVE-2016-9131.nasl

Version: 1.11

Type: remote

Family: DNS

Published: 2017/01/19

Modified: 2018/12/07

Dependencies: 10028

Risk Information

Risk Factor: Medium

CVSS Score Source: CVE-2016-9131

CVSS v2.0

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSS v3.0

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:isc:bind

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2017/01/11

Vulnerability Publication Date: 2017/01/11

Reference Information

CVE: CVE-2016-9131, CVE-2016-9147, CVE-2016-9444, CVE-2016-9778

BID: 95386, 95388, 95390, 95393