Skip to main content

ISC BIND Windows Netmask Processing Vulnerability

Last Update Date: 8 Nov 2013 10:24 Release Date: 8 Nov 2013 3105 Views

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability has been identified in BIND. A remote user on the local network can bypass access control restrictions.

 

On Windows-based systems, an all zero netmask may cause a match on any IPv4 address. A remote user on the local network may be able to access BIND features that are configured to allow access to "localnets".


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Prior to versions 9.6-ESV-R10-P1, 9.8.6-P1, 9.9.4-P1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (9.6-ESV-R10-P1, 9.8.6-P1, 9.9.4-P1).

Vulnerability Identifier


Source


Related Link