ISC BIND 9 RRSIG Query Type Remote Denial of Service Vulnerability
BID:47734
Info
ISC BIND 9 RRSIG Query Type Remote Denial of Service Vulnerability
| Bugtraq ID: | 47734 |
| Class: | Unknown |
| CVE: |
CVE-2011-1907 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2011 12:00AM |
| Updated: | Apr 13 2015 09:30PM |
| Credit: | Mitsuru Shimamura |
| Vulnerable: |
ISC Bind 9.8 |
| Not Vulnerable: |
ISC Bind 9.8.0-P1 |
Discussion
ISC BIND 9 RRSIG Query Type Remote Denial of Service Vulnerability
ISC BIND is prone to a remote denial-of-service vulnerability because the software fails to properly handle certain record types.
An attacker can exploit this issue to cause the application process to crash, denying service to legitimate users.
NOTE: This issue only affects BIND users who use the RPZ feature configured for RRset replacement.
ISC BIND version 9.8.0 is vulnerable.
ISC BIND is prone to a remote denial-of-service vulnerability because the software fails to properly handle certain record types.
An attacker can exploit this issue to cause the application process to crash, denying service to legitimate users.
NOTE: This issue only affects BIND users who use the RPZ feature configured for RRset replacement.
ISC BIND version 9.8.0 is vulnerable.
Exploit / POC
ISC BIND 9 RRSIG Query Type Remote Denial of Service Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
ISC BIND 9 RRSIG Query Type Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ISC BIND 9 RRSIG Query Type Remote Denial of Service Vulnerability
References:
References: