Vulnerability Note VU#142646
ISC BIND 9 named denial of service vulnerability
Overview
ISC BIND 9 contains a remote packet denial of service vulnerability when running as an authoritative or recursive server.
Description
According to ISC: A defect in the affected BIND 9 versions allows an attacker to remotely cause the "named" process to exit using a specially crafted packet. This defect affects both recursive and authoritative servers. The code location of the defect makes it impossible to protect BIND using ACLs configured within named.conf or by disabling any features at compile-time or run-time. |
Impact
A remote, unauthenticated attacker can cause the named daemon to crash creating a denial of service condition. |
Solution
Apply an update |
Vendor Information
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Debian GNU/Linux | Affected | - | 20 Jul 2011 |
| Internet Systems Consortium | Affected | 16 Jun 2011 | 20 Jul 2011 |
| Mandriva S. A. | Affected | - | 20 Jul 2011 |
| Red Hat, Inc. | Affected | - | 20 Jul 2011 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
Credit
Thanks to Internet Systems Consortium for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2011-2464
- Date Public: 05 Jul 2011
- Date First Published: 05 Jul 2011
- Date Last Updated: 20 Jul 2011
- Severity Metric: 17.85
- Document Revision: 14
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify