CVE-2011-2465: Low severity isc bind 9 vulnerability
Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2465?
CVE-2011-2465 is rated as a medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2011-2465?
To fix CVE-2011-2465, update ISC BIND to versions 9.8.1-P1 or higher, or ensure that recursion is disabled if using affected versions.
What products are affected by CVE-2011-2465?
CVE-2011-2465 affects ISC BIND versions 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1.
Can CVE-2011-2465 be exploited remotely?
Yes, CVE-2011-2465 can be exploited remotely by sending malicious queries to the affected BIND server.
What type of attack does CVE-2011-2465 enable?
CVE-2011-2465 can enable an attacker to carry out a denial of service attack, causing the named daemon to crash.