Overview
ISC BIND 9 contains a remote crashing vulnerability when running with certain RPZ configurations.
Description
According to ISC: A defect in the affected versions of BIND could cause the "named" process to exit when queried, if the server has recursion enabled and was configured with an RPZ zone containing certain types of records. Specifically, these are any DNAME record and certain kinds of CNAME records. |
Impact
A remote, unauthenticated attacker can cause the named daemon to crash creating a denial of service condition. |
Solution
Apply an update |
According to ISC: |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Internet Systems Consortium for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2011-2465 |
Severity Metric: | 17.85 |
Date Public: | 2011-07-05 |
Date First Published: | 2011-07-05 |
Date Last Updated: | 2011-07-07 14:21 UTC |
Document Revision: | 15 |