Vulnerability Development mailing list archives

Re: Possible DOS in Bind 8.2.2-P5


From: Daniel Roesen <droesen () ENTIRE-SYSTEMS COM>
Date: Thu, 9 Nov 2000 03:17:53 +0100

On Tue, Nov 07, 2000 at 07:57:22PM +0100, Fabio Pietrosanti (naif) wrote:
playing with bind and ZXFR feature ( zone transfer compressed with a
possible insecure execlp("gzip", "gzip", NULL); ), i discovered a
Denial Of Service against Bind 8.2.2-P5 .

please see my discussion on:

http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=20546

a recursive query for an RR not cached/known on the victim nameserver
after the ZXFR attempt triggers the crash.


Best regards,
Daniel

-- 
----------------------------------------------------------------------
entire systems GmbH         | droesen () entire-systems com
Internet Services           | Phone: +49 2624 9550-55 
Ferbachstrasse 12           | Fax:   +49 2624 9550-20
D-56203 Hoehr-Grenzhausen   | http://www.entire-systems.com/
----------------------------------------------------------------------

Attachment: _bin
Description:


Current thread: