ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability
BID:41730
Info
ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability
| Bugtraq ID: | 41730 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0213 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2010 12:00AM |
| Updated: | Apr 13 2015 09:29PM |
| Credit: | Marco Davids of SIDN |
| Vulnerable: |
S.u.S.E. openSUSE 11.3 ISC BIND 9.7.1 P1 ISC BIND 9.7.1 |
| Not Vulnerable: |
ISC BIND 9.7.1-P2 |
Discussion
ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability
ISC BIND is prone to a remote denial-of-service vulnerability because the software fails to handle certain record types.
An attacker can exploit this issue to cause the application to fall into an infinite loop, denying service to legitimate users.
BIND versions 9.7.1 and 9.7.1-P1 are vulnerable.
ISC BIND is prone to a remote denial-of-service vulnerability because the software fails to handle certain record types.
An attacker can exploit this issue to cause the application to fall into an infinite loop, denying service to legitimate users.
BIND versions 9.7.1 and 9.7.1-P1 are vulnerable.
Exploit / POC
ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability
An attacker can use readily available network utilities.
An attacker can use readily available network utilities.
Solution / Fix
ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability
References:
References: