REDHAT-BUG-2503721: High severity Internet Systems Consortium BIND 9 vulnerability
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2503721?
The severity of REDHAT-BUG-2503721 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2503721?
To fix REDHAT-BUG-2503721, update the Internet Systems Consortium BIND 9 to the latest version that addresses this vulnerability.
What are the potential impacts of REDHAT-BUG-2503721?
The potential impacts of REDHAT-BUG-2503721 include the possibility of defeating RPZ rules and causing unexpected exits during DNS query processing.
Who is affected by REDHAT-BUG-2503721?
Users of Internet Systems Consortium BIND 9 that utilize RPZ with wildcard CNAME policies are affected by REDHAT-BUG-2503721.
Is there a workaround for REDHAT-BUG-2503721?
Currently, the recommended action for REDHAT-BUG-2503721 is to apply the available patches, as no specific workaround is suggested.