ISC BIND RDATA Handling Assertion Failure Denial of Service Vulnerability
Last Update Date:
30 Jul 2013 14:12
Release Date:
30 Jul 2013
4024
Views
RISK: High Risk
TYPE: Servers - Network Management
A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error when parsing RDATA within a DNS query and can be exploited to trigger a REQUIRE assertion and crash the server via a specially crafted query.
Note: This is currently being exploited in the wild.
Impact
- Denial of Service
System / Technologies affected
- ISC BIND 9.8.x
- ISC BIND 9.9.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to a fixed version.
Vulnerability Identifier
Source
Related Link
Share with