Welcome, Guest

Nortel Response to Potential Vunerability VU#927905 - BIND 8 May Allow Cache Poisoning Attack

Description: Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories On Aug 21, 2007, Internet Systems Consortium (ISC) announced a new vulnerability in BIND 8. Additionally, Sun Microsystems has released a patch to address this issue in Solaris. Some Nortel products may contain this software as a component. This bulletin provides per-product recommendations for the Nortel products which are potentially affected by these new vulnerabilities. See also: http://sunsolve.sun.com/search/document.do?assetkey=1-26-103063-1 The Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS) implementation from Internet Systems Consortium (ISC). Version 8 of the BIND software uses a weak algorithm to generate DNS query identifiers. This condition allows an attacker to reliably guess the next query ID, thereby allowing for DNS cache poisoning attacks. ISC states that this bug only affects outgoing queries, generated by BIND 8 to answer questions as a resolver, or when it is looking up data for internal uses, such as when sending NOTIFY messages to slave name servers.
Type: Security Advisories
Number: 2007008410, Rev 1
Status: Retired
Date: 2007-10-30


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to Potential Vunerability VU#927905 - BIND 8 May Allow Cache Poisoning Attack
Checksum: faaecd1b7285cf3d71655611aca5ff7d  [MD5]
[pdf] 23393 bytes English  




Associated Products
Application Server 5200
BroadBand STP
Bulletin temp product
Business Communications Manager 200
Business Communications Manager 400
Business Communications Manager 1000
CDMA Networks
CDMA SuperNode Data Manager
Circuit Switching
Communication Server 1000 Telephony Manager
Communication Server 2100
DMS-100 SSP
DMS-100/200 Local Switching Systems
DMS-250
DMS-500
DMS-Global Services Platform
DMS-STP
DMS-STP/SSP IntegratedNode (INode)
Enterprise Policy Manager
Extended Peripheral Module (XPM)
GSM Networks
GSM-UMTS Home Location Register
GSM-UMTS Mobile Switching Center Server
 
GSM-UMTS SuperNode Data Manager
Integrated Access - Cable
IP Address Domain Manager
Meridian SL-100
Mobile Voice Client 2050
Multimedia Communication Server 5100
Multiservice Data Manager (MDM)
Optical Multiservice Edge 6500
Optivity Policy Services for Business Policy Switch
Optivity Telephony Manager for SL-100
Packet Transit - IP
Periphonics Common Channel Signaling Server (CCSS)
Periphonics Computer Telephony Extension (CTX)
Periphonics Speech Platform
Policy Services application
Self-Service Portfolio
Spectrum Peripheral Module (SPM)
Speech and Self-Service
SuperNode Data Manager
Survivable Remote Gateway 200/400
UMTS Networks
Universal Access - IP
XA-Core