ISC BIND Record Handling Lockup Vulnerability
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error when handling queries for certain records and can be exploited to cause the named process to lockup.
Successful exploitation requires a combination of RDATA to be loaded into a nameserver (e.g. via cache or an authoritative zone).
Impact
- Denial of Service
System / Technologies affected
- ISC BIND 9.6.x
- ISC BIND 9.7.x
- ISC BIND 9.8.x
- ISC BIND 9.9.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to a fixed release.
https://kb.isc.org/article/AA-00801 - For Oracle Solaris
https://blogs.oracle.com/sunsecurity/entry/cve_2012_5166_denial_of
Vulnerability Identifier
Source
Related Link
Share with