USN-7241-1: Bind vulnerabilities
Toshifumi Sakaguchi discovered that Bind incorrectly handled many records in the additional section. A remote attacker could possibly use this issue to cause Bind to consume CPU resources, leading to a denial of service. (CVE-2024-11187) Jean-François Billaud discovered that the Bind DNS-over-HTTPS implementation incorrectly handled a heavy query load. A remote attacker could possibly use this issue to cause Bind to consume resources, leading to a denial of service. (CVE-2024-12705)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7241-1?
The severity of USN-7241-1 is considered to be high due to the potential for denial of service caused by excessive CPU consumption.
How do I fix USN-7241-1?
To fix USN-7241-1, update the Bind9 package to the appropriate version specified for your Ubuntu release.
What are the consequences of exploiting USN-7241-1?
Exploiting USN-7241-1 may allow remote attackers to consume CPU resources, resulting in service outages.
Which versions of Bind9 are affected by USN-7241-1?
USN-7241-1 affects multiple versions of Bind9, specifically those prior to 1:9.20.0-2ubuntu3.1 and versions associated with 9.18.30 in various Ubuntu releases.
Who discovered the vulnerability in USN-7241-1?
The vulnerability in USN-7241-1 was discovered by Toshifumi Sakaguchi and Jean-François Billaud.