Описание
An inapplicable NSEC record may be accepted by a named resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
A flaw was found in BIND 9. A remote attacker could exploit this by providing an inapplicable NSEC (Next Secure) record to a named resolver. This could allow the attacker to mask the existence of a victim's wildcard DNS (Domain Name System) record, potentially leading to a misrepresentation of DNS information.
Отчет
This Moderate impact flaw in BIND 9 allows a remote attacker to mask the existence of DNS wildcard records by providing specially crafted NSEC records to a named resolver. While the attack complexity is high, successful exploitation could lead to a misrepresentation of DNS information, potentially affecting services relying on accurate DNS resolution.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 6 | bind | Not affected | ||
| Red Hat Enterprise Linux 7 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 8 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 8 | bind9.16 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 9 | bind9.18 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | dhcp | Not affected | ||
| Red Hat Hardened Images | bind | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
(An inapplicable NSEC record may be accepted by a `named` resolver as p ...)
An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
An inapplicable NSEC record may be accepted by a `named` resolver as p ...
An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
5.9 Medium
CVSS3