Welcome, Guest

Nortel Response to ISC:DNS:BIND 9 Vulnerabilities in Default ACL and Weak Query IDs

Description: Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories On July 24, 2007, Internet Systems Consortium (ISC) announced 2 new vulnerabilities with their BIND implementation of DNS. Some Nortel products may contain this software as a component. This bulletin provides per-product recommendations for the Nortel products which are potentially affected by these new vulnerabilities. The following 2 vulnerabilities are addressed: 1) BIND 9: allow-query-cache/allow-recursion default acls not set - CVE-2007-2925 The default access control lists (acls) are not being correctly set. If not set anyone can make recursive queries and/or query the cache contents. 2) BIND 9: cryptographically weak query ids - CVE-2007-2926 The DNS query id generation is vulnerable to cryptographic analysis which provides a 1 in 8 chance of guessing the next query id for 50% of the query ids. This can be used to perform cache poisoning by an attacker. This bug only affects outgoing queries, generated by BIND 9 to answer questions as a resolver, or when it is looking up data for internal uses, such as when sending NOTIFYs to slave name servers. All users are encouraged to upgrade.
Type: Security Advisories
Number: 2007008208, Rev 2
Status: Retired
Date: 2007-12-10


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to ISC:DNS:BIND 9 Vulnerabilities in Default ACL and Weak Query IDs
Checksum: faf973ae05f29f55e96a5a08136c36f4  [MD5]
[pdf] 22586 bytes English  




Associated Products
Application Server 5200
BroadBand STP
Business Communications Manager 200
Business Communications Manager 400
Business Communications Manager 1000
Business Communications Manager 50
CDMA Networks
CDMA SuperNode Data Manager
Circuit Switching
Communication Server 1000 Telephony Manager
Communication Server 2000
Communication Server 2000 Core Manager
Communication Server 2000 Session Server Trunks
Communication Server 2000-Compact
Communication Server 2100
DMS-100 SSP
DMS-100/200 Local Switching Systems
DMS-250
DMS-500
DMS-Global Services Platform
DMS-STP
DMS-STP/SSP IntegratedNode (INode)
Extended Peripheral Module (XPM)
 
GSM Networks
GSM-UMTS Home Location Register
GSM-UMTS Mobile Switching Center Server
GSM-UMTS SuperNode Data Manager
Integrated Access - Cable
Integrated Element Management System (IEMS)
IP Address Domain Manager
Meridian SL-100
Mobile Voice Client 2050
Multimedia Communication Server 5100
Optivity Telephony Manager for SL-100
Packet Transit - AAL2
Packet Transit - IP
Packet Trunking - AAL1
Spectrum Peripheral Module (SPM)
SuperNode Data Manager
Survivable Remote Gateway 200/400
UMTS Networks
Universal Access - AAL1
Universal Access - IP
Wireless Access Point 7215
Wireless Access Point 7220
XA-Core