A fix is available
APAR status
Closed as program error.
Error description
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
Local fix
Problem summary
If /etc/named.conf file is not configured with trusted subnet parameters, AIX named9 will allow user request from anywhere to do the recursive query via named, and query named's unauthoritative cache entry. This is a potential "Denial of Service" vulnerability.
Problem conclusion
AIX named9 code is modified to allow recursive queries or cache queries only to the hosts within the subnet of the DNS server (ie localhost, localnet) by default, if /etc/named.conf is not configured with any ACL's using 'allow-query-cache' or 'allow-recursion' options.
Temporary fix
Comments
6100-08 - use AIX APAR IV60990 6100-09 - use AIX APAR IV57729 6100-09 - use AIX APAR IV57729 7100-02 - use AIX APAR IV61090 7100-03 - use AIX APAR IV61027 7100-04 - use AIX APAR IV61067
APAR Information
APAR number
IV61027
Reported component name
AIX V7.1
Reported component ID
5765H4000
Reported release
710
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Submitted date
2014-05-29
Closed date
2014-05-29
Last modified date
2016-05-10
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX V7.1
Fixed component ID
5765H4000
Applicable component levels
R710 PSY U865037
UP14/10/29 I 1000
PTF to Fileset Mapping
U865037 bos.net.tcp.server 7.1.3.30
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSMV87","label":"AIX 6.1 Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSMVAX","label":"AIX Express Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11R","label":"AIX 7.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
10 May 2016