Skip to main content

ISC BIND Deleted Domain Name Resolving Vulnerability

Last Update Date: 9 Feb 2012 10:01 Release Date: 9 Feb 2012 5314 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerability is caused due to an error within the cache update policy, which does not properly handle revoked domain names. This can be exploited to keep the domain name resolvable after being deleted from registration.
 


Impact

  • Security Restriction Bypass

System / Technologies affected

  • ISC BIND 9.2.x
  • ISC BIND 9.3.x
  • ISC BIND 9.4.x
  • ISC BIND 9.5.x
  • ISC BIND 9.6.x
  • ISC BIND 9.7.x
  • ISC BIND 9.8.x

Solutions

  • The vendor is currently working a fix.

Vulnerability Identifier


Source


Related Link