https://seclists.org/oss-sec/2025/q1/90: ISC has disclosed two vulnerabilities in BIND 9 (CVE-2024-11187, CVE-2024-12705)
Published Jan 29, 2025
·Updated
Affected Software
1 affected component
ISC BIND 9
CVE-2024-11187 has been classified with a high severity due to its potential impact on the security of DNS operations.
To fix CVE-2024-11187, upgrade to the latest version of BIND 9 as recommended by ISC.
CVE-2024-12705 is a vulnerability in BIND 9 that may allow attackers to exploit DNS server functionality.
CVE-2024-12705 is considered a critical vulnerability that could lead to unauthorized access or service disruption.
Yes, patches for both CVE-2024-11187 and CVE-2024-12705 are included in the latest versions of BIND 9 available from ISC.