DNS patches cause problems, developers admit

Patches have slowed servers running BIND and crippled some systems versions of Windows Server.

Patches released earlier this month to quash a critical bug in the Domain Name System (DNS) have slowed servers running BIND, the Internet's most popular DNS software, and crippled some systems versions of Windows Server.

Paul Vixie, who heads the Internet Systems Consortium (ISC), the group responsible for the BIND (Berkeley Internet Name Domain) software, acknowledged issues with the July 8 fix that was rolled out as part of a multi-vendor update meant to patch a cache poisoning flaw discovered months before by researcher Dan Kaminsky.

"During the development cycle we became aware of a potential performance issue on high-traffic recursive servers, defined as those seeing a query volume of greater than 10,000/queries per second," said Vixie in a message posted Monday afternoon to a BIND mailing list. "Given the limited time frame and associated risks we chose to finish the patches ASAP and accelerate our work on the next point releases that would address the high-volume server performance concerns.

"Our immediate goal was to make patches publicly available as soon as possible," Vixie explained.

Vixie wasn't specific about the extent of the performance problems facing high-volume DNS servers, but said that a second round of patches, due later this week, will remedy port allocation issues and "allow TCP queries and zone transfers while issuing as many outstanding UDP queries as possible."

Versions of the second update, which will be designated P2 when they're unveiled, are currently available in beta form for BIND 9.4.3 and BIND 9.5.1.

However, Vixie stressed that administrators shouldn't roll back the July 8 patched editions even if their servers were running slowly. "Until the release of the -P2 code, it is imperative that you run a -P1 version of BIND on your caching resolvers," he said. "The vulnerability is of more concern than a slow server."

The flaw Kaminsky uncovered in February makes it much easier than originally thought to insert bogus information into the Internet's routing infrastructure. A successful attack would let criminals silently redirect requests for a legitimate site to a bogus one set up to skim personal information, such as passwords to online banking accounts, from duped users.

Earlier this month, when Kaminsky announced that the vulnerability had been patched by several vendors, including ISC, Microsoft and Cisco Systems, he applauded their quick cooperation. "I want to get a lot of credit to the vendors here," he added in an interview last week. "The vendors were everything that the security community ever could have asked for," he said, referring to the resources they allocated to the problem and the speed with which they cranked out patches.

Patching the DNS flaw became more important last week after hackers took exploit code public.

ISC wasn't the only vendor involved in first-round DNS patching that has issued a mea culpa. Two weeks ago, Microsoft confirmed that the July 8 DNS update, tagged as MS08-037, was crippling machines running Windows Small Business Server, a suite based on, among other programs, Windows Server 2003.

"Some customers have reported seeing random problems with services after installing MS08-037," reported several Microsoft engineers in a post to the Small Business Server (SBS) blog on July 17.

One SBS component that might fail to start, said Microsoft, was the IPSEC service, which would knock the server off the network.

Last Friday, the company unveiled a pair of support documents that spelled out the patch's unintended side effects, but also added Exchange Server 2003 and Internet Security and Acceleration (ISA) Server to the affected list.

A second issue involves every supported version of Windows, ranging from Windows 2000, XP and Vista to Server 2003 and Server 2008. "You may experience issues with UDP-dependent network services after you install the Domain Name System (DNS) Server service security update 953230 (MS08-037) and then restart the computer," Microsoft said.

In both instances, Microsoft offered workarounds in the support documents but did not say whether, or when, the original DNS patch would be re-released. A company spokesman did not know of any plans to re-issue MS08-037, but was unable to immediately verify that with the team at the Microsoft Security Response Center (MSRC).

Robert McMillan of the IDG News Service contributed to this story.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Show Comments

Most Popular Reviews

Latest News Articles


PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?