CVE-2015-1349: Medium severity isc bind 9 vulnerability
It was reported that a problem with trust anchor management can cause named to crash, affecting BIND versions 9.7.0+.
ISC developers believe that it will be very difficult for this to be triggered in most cases, requiring DNSSEC validation amongst other factors.
ISC will not be producing patches specifically for BIND 9.8 or BIND 9.6-ESV, both of which are beyond their End of Life (EOL) and are no longer supported by ISC.
Patches that correct this issue for ISC BIND 9.10.1 and ISC BIND 9.9.6 are attached to this Bugzilla.
Other sources
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1349?
CVE-2015-1349 has a moderate severity level, primarily affecting the stability of BIND when DNSSEC validation is used.
How do I fix CVE-2015-1349?
To fix CVE-2015-1349, update BIND to version 9.9.7 or 9.10.2.
Which versions of BIND are affected by CVE-2015-1349?
CVE-2015-1349 affects BIND versions 9.7.0 and above.
Is there a workaround for CVE-2015-1349?
There is no official workaround aside from upgrading to a patched version of BIND.
What type of vulnerability is CVE-2015-1349?
CVE-2015-1349 is a trust anchor management vulnerability that can lead to a crash in BIND.