QID 15148
Date Published: 2023-07-25
QID 15148: ISC BIND Denial of Service (DoS) Vulnerability (CVE-2015-4620)
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
A very uncommon combination of zone data has been found that triggers a bug in BIND, with the result that named will exit with a "REQUIRE" failure in name.c when validating the data returned in answer to a recursive query.
BIND Affected versions:
BIND 9.7.1 -> 9.7.7
BIND 9.8.0 -> 9.8.8
BIND 9.9.0 -> 9.9.7
BIND 9.10.0 -> 9.10.2-P1
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
A recursive resolver that is performing DNSSEC validation can be deliberately terminated by any attacker who can cause a query to be performed against a maliciously constructed zone. This will result in a denial of service to clients who rely on that resolver.
Workaround:
Disabling DNSSEC validation prevents exploitation of this defect but is not generally recommended. The recommended solution is to upgrade to a patched version.
- CVE-2015-4620 -
kb.isc.org/docs/aa-01267
CVEs related to QID 15148
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2015-4620 |
|