First published: Mon Dec 06 2010(Updated: )
named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC BIND | =9.6.2-p2 | |
ISC BIND | =9.6.2-p1 | |
ISC BIND | =9.7.0-rc2 | |
ISC BIND | =9.7.1-b1 | |
ISC BIND | =9.7.0-b1 | |
ISC BIND | =9.7.0-a1 | |
ISC BIND | =9.7.0-rc1 | |
ISC BIND | =9.7.0-p2 | |
ISC BIND | =9.6.2 | |
ISC BIND | =9.6.2-b1 | |
ISC BIND | =9.7.2 | |
ISC BIND | =9.7.2-p2 | |
ISC BIND | =9.7.1 | |
ISC BIND | =9.7.0-a3 | |
ISC BIND | =9.7.1-rc1 | |
ISC BIND | =9.7.1-p2 | |
ISC BIND | =9.7.0 | |
ISC BIND | =9.6 | |
ISC BIND | =9.7.0-a2 | |
ISC BIND | =9.7.0-p1 | |
ISC BIND | =9.6-r2 | |
ISC BIND | =9.6-r1 | |
ISC BIND | =9.7.1-p1 | |
ISC BIND | =9.7.2-p1 | |
ISC BIND | =9.7.0-b2 | |
ISC BIND | =9.7.0-b3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.