CVE-1999-0011: Medium severity Data General Dg Ux vulnerability

Published Apr 8, 1998
·
Updated

Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

Affected Software

26 affected components
Data General Dg Ux=y2k_patchr4.11mu05
Data General Dg Ux=y2k_patchr4.20mu03
Data General Dg Ux=y2k_patchr4.12mu03
ISC BIND=4.9
Data General Dg Ux=y2k_patchr4.20mu02
ISC BIND=8
Data General Dg Ux=y2k_patchr4.20mu01
SCO OpenServer=5.0
NEC Asl Ux 4800=11
IBM AIX=4.3
SCO Open Desktop=3.0
Sun SunOS=5.3
NetBSD NetBSD=1.3
IBM AIX=4.2
NetBSD NetBSD=1.3.1
redhat Linux=5.0
Sun SunOS=5.5
SCO UnixWare=2.1
SCO UNIX=3.2v4
Sun SunOS=5.4
SCO UnixWare=7.0
Sun SunOS=5.5.1
redhat Linux=4.2
IBM AIX=4.1
Sun SunOS=5.6
NEC Asl Ux 4800=13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove BIND 4.9 from your environment.

    Uninstall or stop running BIND 4.9 releases; do not operate these versions until a fixed release is made available.

  2. Remove

    Remove BIND 8 Releases from your environment.

    Uninstall or stop running BIND 8 releases; do not operate these versions until a fixed release is made available.

  3. Configuration

    Disable or restrict zone transfers (AXFR/IXFR) so that zone transfers are only allowed to authorized secondary servers or are disabled if not required.

    BIND allow-transfer (zone transfer policy) = restrict to authorized IPs or disable
  4. Compensating control

    Apply network-level controls to mitigate exploitation: restrict DNS zone transfer traffic at the perimeter to trusted hosts, monitor and block suspicious or malformed CNAME-related queries/responses, and isolate vulnerable name servers from untrusted networks until they are replaced.

Event History

Apr 8, 1998
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityWeaknessAffected Software
Sep 29, 1999
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0011?

The severity of CVE-1999-0011 is classified as medium due to its potential to cause Denial of Service.

2

How do I fix CVE-1999-0011?

To fix CVE-1999-0011, administrators should upgrade to a patched version of BIND, specifically versions 4.9.10 or 8.2.3 and later.

3

What systems are affected by CVE-1999-0011?

CVE-1999-0011 affects various systems running BIND versions 4.9 and 8, as well as other platforms such as DG/UX and AIX.

4

What type of vulnerability is CVE-1999-0011?

CVE-1999-0011 is a Denial of Service vulnerability that occurs through exploitation of CNAME records and zone transfers.

5

When was CVE-1999-0011 published?

CVE-1999-0011 was published on January 4, 1999.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203