Vulnerability Note VU#706148
ISC BIND cache vulnerability
Overview
The ISC BIND nameserver contains a vulnerability that could allow a remote attacker to cause a denial of service.
Description
According to ISC: Adding certain types of signed negative responses to cache doesn't clear any matching RRSIG records already in cache. A subsequent lookup of the cached data can cause named to crash (INSIST). |
Impact
A remote attacker could cause the name server on an affected system to crash. ISC notes that this vulnerability affects recursive nameservers irrespective of whether DNSSEC validation is enabled or disabled. |
Solution
Apply an update |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Internet Systems Consortium | Affected | - | 01 Dec 2010 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- https://www.isc.org/software/bind/advisories/cve-2010-3613
- http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories
Credit
Thanks to Internet Systems Consortium for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2010-3613
- Date Public: 01 Dec 2010
- Date First Published: 01 Dec 2010
- Date Last Updated: 16 Dec 2010
- Severity Metric: 7.65
- Document Revision: 22
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.