BIND DNS Server Update Addressing Vulnerability Allowing Remote Code Execution

Corrective updates have been released for stable branches of BIND DNS Server versions 9.11.31 and 9.16.15, as well as the experimental branch 9.17.12 currently in development. These new releases fix three vulnerabilities, one of which (CVE-2021-25216) leads to buffer overflow. On 32-bit systems, this vulnerability can be exploited for remote code execution by sending a specially crafted GSS-TSIG request. On 64-bit systems, the issue is limited to the crash of the named process.

The problem occurs only when the GSS-TSIG mechanism is enabled, which is activated through the tkey-gssapi-keytab and tkey-gssapi-credential settings. GSS-TSIG is disabled in the default configuration and is generally used in mixed environments where BIND works with Active Directory domain controllers or when integrated with Samba.

The vulnerability is caused by an error in the implementation of the SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism), used in GSSAPI to negotiate the methods employed by the client and protection mechanisms. GSSAPI is used as a high-level protocol for secure key exchange using the GSS-TSIG extension during DNS zone dynamic update authentication. proxy server Given that critical vulnerabilities in the embedded SPNEGO implementation have been found previously, this protocol's implementation has been removed from the BIND 9 codebase. For users requiring SPNEGO support, it's recommended to use an external implementation provided by the GSSAPI system library (available in MIT Kerberos and Heimdal Kerberos).

Users of older BIND versions can circumvent the issue by disabling GSS-TSIG in the settings (with the tkey-gssapi-keytab and tkey-gssapi-credential parameters) or by rebuilding BIND without SPNEGO support (using the '--disable-isc-spnego' option in the 'configure' script). Updates in distributions can be tracked on the following pages: Debian, SUSE, Ubuntu, Fedora, Arch Linux, FreeBSD, NetBSD. RHEL and ALT Linux packages are built without embedded SPNEGO support.

Additionally, the updates for BIND address two more vulnerabilities:

Additionally, two more vulnerabilities have been addressed in the discussed updates for BIND:

  • CVE-2021-25215 — crash of the named process when processing DNAME records (redirect handling for some subdomains), leading to the addition of duplicates in the ANSWER section. To exploit the vulnerability on authoritative DNS servers, changes need to be made to the processed DNS zones, and for recursive servers the problematic record can be obtained after querying an authoritative server.
  • CVE-2021-25214 — crash of the named process when processing a specially formatted incoming IXFR request (used for incremental transfer of DNS zone changes between DNS servers). The issue affects only systems that have permitted zone transfers from the attacking server (typically, zone transfers are used for synchronizing master and slave servers and are selectively allowed only for trusted servers). A workaround to protect against this issue is to disable IXFR support by setting 'request-ixfr no;'.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster