https://seclists.org/oss-sec/2024/q3/127: ISC has disclosed four vulnerabilities in BIND 9 (CVE-2024-0760, CVE-2024-1737, CVE-2024-1975, CVE-2024-4076)
Published Jul 31, 2024
·Updated
Affected Software
1 affected component
Internet Systems Consortium BIND 9<9.20, >=9.18
Frequently Asked Questions
1
What is the severity of CVE-2024-1975?
CVE-2024-1975 is a critical vulnerability that can cause CPU resource exhaustion.
2
How do I fix CVE-2024-1975?
To mitigate CVE-2024-1975, upgrade your BIND 9 software to the latest version provided by ISC.
3
What systems are affected by CVE-2024-1975?
CVE-2024-1975 affects all versions of BIND 9 prior to the patched release by ISC.
4
What type of vulnerability is CVE-2024-1975?
CVE-2024-1975 is a Denial of Service vulnerability that exploits the SIG(0) operation in BIND 9.
5
When was CVE-2024-1975 disclosed?
CVE-2024-1975 was disclosed on July 23, 2024.