Executive brief
ISC BIND, a widely used system for translating human-readable domain names into IP addresses, contains a security flaw when specific configuration options are enabled during installation. This flaw allows unauthorized individuals to remotely modify DNS records, which could lead to website redirection, email interception, or service disruptions. Organizations using affected versions may face significant reputational and operational risks if their internet traffic is diverted to malicious sites.
Technical details
The vulnerability exists in ISC BIND when the software is compiled with the '-DALLOW_UPDATES' flag enabled. This configuration allows the DNS server to accept dynamic update requests without sufficient authentication or authorization checks. A remote, unauthenticated attacker can send specially crafted update packets to the server to add, delete, or modify DNS resource records. This can result in DNS cache poisoning or redirection of legitimate traffic to attacker-controlled infrastructure. The issue is rooted in the insecure default behavior of the dynamic update feature in early versions of the software.
Affected products
- ISC BIND
Timeline
- 1997-07-01: disclosed