CVE-1999-0849: Medium severity ISC BIND vulnerability
Denial of service in BIND named via maxdname.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Adjust the named configuration option 'max-dname' to enforce a stricter maximum domain-name size/limits to mitigate the denial-of-service condition triggered via maxdname.
ISC BIND 9 (named) max-dname = set a lower/enforced maximum
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0849?
CVE-1999-0849 is classified as a high severity vulnerability that can cause a denial of service.
How do I fix CVE-1999-0849?
To fix CVE-1999-0849, update BIND to a version that is not affected by this vulnerability.
Which versions of BIND are affected by CVE-1999-0849?
CVE-1999-0849 affects BIND versions 4.9.5, 4.9.6, 4.9.7, and multiple versions of 8.x.
What kind of attack does CVE-1999-0849 facilitate?
CVE-1999-0849 facilitates a denial of service attack by causing BIND named to consume excessive resources.
Is CVE-1999-0849 still a current threat?
CVE-1999-0849 is considered a legacy vulnerability, but systems running outdated versions of BIND may still be at risk.