QID 15153
Date Published: 2024-03-11
QID 15153: ISC BIND Denial of Service (DoS) Vulnerability (CVE-2023-6516)
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
Specific recursive query patterns may lead to an out-of-memory condition.
Affected versions:
BIND 9.16.0 - 9.16.45
BIND Supported Preview Edition 9.16.8-S1 - 9.16.45-S1
Patched Versions:
BIND 9.16.48
BIND Supported Preview Edition 9.16.48-S1
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service using banner.
By exploiting this flaw, an attacker can cause the amount of memory used by a named resolver to go well beyond the configured max-cache-size limit. The effectiveness of the attack depends on a number of environmental factors, but in the worst case the attacker can exhaust all available memory on the host running named, leading to a denial-of-service condition.
- CVE-2023-6516 -
kb.isc.org/docs/cve-2023-6516
CVEs related to QID 15153
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-6516 |
|