PT-2016-3207 · Mit · Hesiod

Carnil

·

Published

2016-05-03

·

Updated

2018-10-21

·

CVE-2016-10152

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hesiod version 3.2.1
Description The issue is related to the read config file function in lib/hesiod.c, which falls back to the ".athena.mit.edu" default domain when opening the configuration file fails. This allows remote attackers to gain root privileges by poisoning the DNS cache. The exploitation of this issue can lead to a remote attacker gaining root privileges by damaging the integrity of the DNS data through DNS cache manipulation.
Recommendations For Hesiod version 3.2.1, consider disabling the read config file function as a temporary workaround until a patch is available. Restrict access to the DNS cache to minimize the risk of exploitation. Avoid using the default domain ".athena.mit.edu" in the configuration file to prevent potential manipulation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02496
CVE-2016-10152
DLA-796-1

Affected Products

Hesiod