CVE-1999-0010: Medium severity Data General Dg Ux vulnerability
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
BIND 8from your environment.If BIND 8 is not required, uninstall the BIND 8 package and stop/remove its service to eliminate the vulnerable software from the environment.
- Configuration
Update BIND (named.conf) to restrict allow-query to trusted client IP ranges and disable recursion for queries from untrusted/external networks to reduce exposure to maliciously formatted DNS messages.
BIND 8 allow-query / recursion = restrict to trusted IPs; disable recursion for external networks - Compensating control
Deploy network-level mitigations: restrict incoming DNS traffic to trusted sources using firewall/ACLs, rate-limit DNS queries, and isolate DNS servers from untrusted networks to mitigate denial-of-service attempts using malformed DNS messages.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0010?
CVE-1999-0010 has been classified as a denial of service vulnerability that can severely impact the availability of affected systems.
How do I fix CVE-1999-0010?
To fix CVE-1999-0010, update BIND to the latest version that addresses this vulnerability.
Which software is affected by CVE-1999-0010?
CVE-1999-0010 affects various versions of BIND 8 and other specific systems listed in the vulnerability report.
What kind of attack is associated with CVE-1999-0010?
CVE-1999-0010 is associated with attacks leveraging maliciously formatted DNS messages to cause denial of service.
Is CVE-1999-0010 still a risk today?
While CVE-1999-0010 pertains to older software, unpatched systems may still be vulnerable to exploitation.