CVE-1999-0011: Medium severity Data General Dg Ux vulnerability
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
BIND 4.9from your environment.Uninstall or stop running BIND 4.9 releases; do not operate these versions until a fixed release is made available.
- Remove
Remove
BIND 8 Releasesfrom your environment.Uninstall or stop running BIND 8 releases; do not operate these versions until a fixed release is made available.
- Configuration
Disable or restrict zone transfers (AXFR/IXFR) so that zone transfers are only allowed to authorized secondary servers or are disabled if not required.
BIND allow-transfer (zone transfer policy) = restrict to authorized IPs or disable - Compensating control
Apply network-level controls to mitigate exploitation: restrict DNS zone transfer traffic at the perimeter to trusted hosts, monitor and block suspicious or malformed CNAME-related queries/responses, and isolate vulnerable name servers from untrusted networks until they are replaced.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0011?
The severity of CVE-1999-0011 is classified as medium due to its potential to cause Denial of Service.
How do I fix CVE-1999-0011?
To fix CVE-1999-0011, administrators should upgrade to a patched version of BIND, specifically versions 4.9.10 or 8.2.3 and later.
What systems are affected by CVE-1999-0011?
CVE-1999-0011 affects various systems running BIND versions 4.9 and 8, as well as other platforms such as DG/UX and AIX.
What type of vulnerability is CVE-1999-0011?
CVE-1999-0011 is a Denial of Service vulnerability that occurs through exploitation of CNAME records and zone transfers.
When was CVE-1999-0011 published?
CVE-1999-0011 was published on January 4, 1999.