First published: Wed Jul 25 2012(Updated: )
Race condition in the ns_client structure management in ISC BIND 9.9.x before 9.9.1-P2 allows remote attackers to cause a denial of service (memory consumption or process exit) via a large volume of TCP queries.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BIND 9 | =9.9.0 | |
BIND 9 | =9.9.0-a1 | |
BIND 9 | =9.9.0-a2 | |
BIND 9 | =9.9.0-a3 | |
BIND 9 | =9.9.0-b1 | |
BIND 9 | =9.9.0-b2 | |
BIND 9 | =9.9.0-rc1 | |
BIND 9 | =9.9.0-rc2 | |
BIND 9 | =9.9.0-rc3 | |
BIND 9 | =9.9.0-rc4 | |
BIND 9 | =9.9.1 | |
BIND 9 | =9.9.1-p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3868 has a high severity rating due to its potential to cause denial of service.
To fix CVE-2012-3868, upgrade ISC BIND to version 9.9.1-P2 or later.
Exploitation of CVE-2012-3868 can lead to memory consumption or process exit, resulting in denial of service.
CVE-2012-3868 affects BIND version 9.9.0 through 9.9.1-P1.
Yes, CVE-2012-3868 can be exploited by remote attackers via a large volume of TCP queries.