CVE-1999-0837: Critical severity ISC BIND vulnerability
Denial of service in BIND by improperly closing TCP sessions via solinger.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to BIND's TCP DNS service (TCP port 53) to trusted sources (firewall/ACLs) and apply rate-limiting or connection throttling on TCP connections to the DNS server to mitigate potential denial-of-service via improper TCP session closes (SO_LINGER).
- Operational
Monitor BIND instances for service degradation or crashes related to TCP connections and closely follow vendor/security advisories for this SO_LINGER-related issue; plan to apply any vendor-supplied patch or update addressing this vulnerability as soon as it is released.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0837?
CVE-1999-0837 is classified as a denial of service vulnerability.
How do I fix CVE-1999-0837?
To fix CVE-1999-0837, upgrade to a patched version of BIND beyond 8.2.1.
Which software is affected by CVE-1999-0837?
CVE-1999-0837 affects ISC BIND 8.2 and 8.2.1, as well as Sun SunOS 5.7 and Solaris 7.0.
What are the consequences of CVE-1999-0837?
The consequence of CVE-1999-0837 is that it may lead to a denial of service by improperly closing TCP sessions.
Is CVE-1999-0837 still relevant today?
While CVE-1999-0837 is an older vulnerability, systems running the affected software remain at risk if they have not been updated.