Junglewise Threat Intelligence

CVE-1999-1499: ISC BIND symlink vulnerability in named_dump.db and named.stats

CVE-1999-1499 · Severity: low · CVSS 2.1 · Published 1998-04-10

Technologies: Isc Bind. Vendors: Isc.

Executive brief

ISC BIND is a widely used system for translating human-readable domain names into IP addresses. A security flaw in older versions allows a local user on the server to trick the system into overwriting or destroying sensitive files. This occurs when the system administrator stops the service, potentially leading to data loss or system instability.

Technical details

A symbolic link (symlink) vulnerability exists in ISC BIND versions 4.9 and 8.1. When the 'named' process receives a SIGINT or SIGIOT signal, it attempts to write debug or statistics information to 'named_dump.db' or 'named.stats' in a predictable location. A local attacker can create a symbolic link with one of these filenames pointing to a critical system file. When the root user or a system process sends the termination signal, BIND follows the symlink and overwrites the target file with its own output, leading to unauthorized file modification or destruction.

Affected products

  • ISC BIND 4.9, 8.1

Timeline

  • 1998-04-10: disclosed
  • 1998-04-10: advisory

References

Related threats