CVE-2011-1907: Medium severity isc bind 9 vulnerability
Published May 9, 2011
·Updated
ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG query.
Affected Software
1 affected component
ISC BIND=9.8.0
Event History
May 9, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1907?
CVE-2011-1907 has a medium severity level due to its potential to cause denial of service.
2
How do I fix CVE-2011-1907?
To fix CVE-2011-1907, upgrade ISC BIND to version 9.8.0-P1 or later where the vulnerability is patched.
3
What are the consequences of exploiting CVE-2011-1907?
Exploiting CVE-2011-1907 can lead to an assertion failure and cause the BIND daemon to crash.
4
Which versions of BIND are affected by CVE-2011-1907?
CVE-2011-1907 affects ISC BIND version 9.8.0 and earlier versions.
5
Does CVE-2011-1907 allow remote attacks?
Yes, CVE-2011-1907 allows remote attackers to exploit the vulnerability through RRSIG queries.