A vulnerability in the BIND DNS server that does not preclude remote code execution

Corrective updates have been released for the stable branches of the BIND DNS server 9.11.28 and 9.16.12, as well as the experimental branch 9.17.10 currently in development. The new releases address a vulnerability (CVE-2020-8625) that leads to a buffer overflow and could potentially allow remote code execution by an attacker. No evidence of active exploits has been detected yet.

The issue is caused by a bug in the implementation of the SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism) mechanism used in GSSAPI to negotiate between the client and proxy server Given that critical vulnerabilities in the embedded SPNEGO implementation have been found previously, this protocol's implementation has been removed from the BIND 9 codebase. For users requiring SPNEGO support, it's recommended to use an external implementation provided by the GSSAPI system library (available in MIT Kerberos and Heimdal Kerberos).

The vulnerability affects systems where the use of GSS-TSIG is enabled (for example, if the tkey-gssapi-keytab and tkey-gssapi-credential settings are used). GSS-TSIG is typically applied in mixed environments where BIND is used alongside controllers domain Active Directory, or when integrating with Samba. By default, GSS-TSIG is disabled.

A workaround to block the issue that does not require disabling GSS-TSIG is to build BIND without support for the SPNEGO mechanism, which can be disabled by specifying the ‘--disable-isc-spnego’ option when running the ‘configure’ script. The issue remains unpatched in the distributions. You can track the appearance of updates on the following pages: Debian, RHEL, SUSE, Ubuntu, Fedora, Arch Linux, FreeBSD, NetBSD.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster