CVE-2011-1910: Medium severity isc bind 9 vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1910 to the following vulnerability:
A BIND 9 DNS server set up to be a caching resolver is vulnerable to a user querying a domain with very large resource record sets (RRSets) when trying to negatively cache a response. This can cause the BIND 9 DNS server (named process) to crash.
http://www.isc.org/software/bind/advisories/cve-2011-1910
Other sources
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1910?
The severity of CVE-2011-1910 is classified as high due to its potential to allow remote code execution.
How do I fix CVE-2011-1910?
To fix CVE-2011-1910, upgrade your BIND version to 9.7.2 or later, or apply the appropriate patch provided by ISC.
What software versions are affected by CVE-2011-1910?
CVE-2011-1910 affects several versions of ISC BIND, including 9.6.1, 9.6.2, and earlier.
Is it safe to continue using software affected by CVE-2011-1910?
It is not safe to continue using affected software until it has been updated or patched to mitigate the vulnerability.
What type of attacks could exploit CVE-2011-1910?
CVE-2011-1910 can be exploited through crafted DNS queries that trigger a denial of service or remote code execution, impacting system availability.