PT-2012-4704 · Isc+2 · Bind-Dyndb-Ldap+2

Sigbjorn Lie

·

Published

2012-08-03

·

Updated

2017-08-29

·

CVE-2012-3429

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions bind-dyndb-ldap version 1.1.0rc1 and earlier
Description The issue arises from the dns to ldap dn escape function in src/ldap convert.c, which fails to properly escape distinguished names (DN) for LDAP queries. This allows remote DNS servers to cause a denial of service, specifically a named service hang, by including a "$" character in a DN within a DNS query.
Recommendations For bind-dyndb-ldap version 1.1.0rc1 and earlier, consider disabling the dns to ldap dn escape function until a patch is available to properly escape distinguished names and prevent the denial of service.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_1139
CVE-2012-3429
RHSA-2012:1139
RHSA-2012_1139

Affected Products

Centos
Red Hat
Bind-Dyndb-Ldap