First published: Fri Jan 25 2013(Updated: )
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BIND 9 | =9.9.0 | |
BIND 9 | =9.9.0-a1 | |
BIND 9 | =9.9.0-a2 | |
BIND 9 | =9.9.0-a3 | |
BIND 9 | =9.9.0-b1 | |
BIND 9 | =9.9.0-b2 | |
BIND 9 | =9.9.0-rc1 | |
BIND 9 | =9.9.0-rc2 | |
BIND 9 | =9.9.0-rc3 | |
BIND 9 | =9.9.0-rc4 | |
BIND 9 | =9.9.1 | |
BIND 9 | =9.9.1-p1 | |
BIND 9 | =9.9.1-p2 | |
BIND 9 | =9.9.2 | |
redhat enterprise Linux desktop | =6.0 | |
Red Hat Enterprise Linux HPC Node | =6.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server aus | =6.4 | |
redhat enterprise Linux server eus | =6.4.z | |
redhat enterprise Linux workstation | =6.0 | |
BIND 9 | =9.8.0 | |
BIND 9 | =9.8.0-a1 | |
BIND 9 | =9.8.0-b1 | |
BIND 9 | =9.8.0-p1 | |
BIND 9 | =9.8.0-p2 | |
BIND 9 | =9.8.0-p4 | |
BIND 9 | =9.8.0-rc1 | |
BIND 9 | =9.8.1 | |
BIND 9 | =9.8.1-b1 | |
BIND 9 | =9.8.1-b2 | |
BIND 9 | =9.8.1-b3 | |
BIND 9 | =9.8.1-p1 | |
BIND 9 | =9.8.1-rc1 | |
BIND 9 | =9.8.2-b1 | |
BIND 9 | =9.8.2-rc1 | |
BIND 9 | =9.8.2-rc2 | |
BIND 9 | =9.8.3 | |
BIND 9 | =9.8.3-p1 | |
BIND 9 | =9.8.3-p2 | |
BIND 9 | =9.8.4 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5689 is classified as a high-severity vulnerability that can lead to a denial of service.
To fix CVE-2012-5689, upgrade to ISC BIND version 9.9.3 or later, which contains patches for this vulnerability.
CVE-2012-5689 can be exploited remotely by sending specially crafted DNS queries for AAAA records.
ISC BIND versions 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1 are affected by CVE-2012-5689.
Exploitation of CVE-2012-5689 may result in assertion failures that cause the named daemon to crash.