Improper Data Handling Affecting bind9 package, versions <9.7.1.dfsg.P2


Severity

Recommended
0.0
low
0
10

Snyk's Security Team recommends NVD's CVSS assessment

    Threat Intelligence

    EPSS
    4.24% (93rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIAN12-BIND9-1542011
  • published 28 Jul 2010
  • disclosed 28 Jul 2010

How to fix?

Upgrade Debian:12 bind9 to version 9.7.1.dfsg.P2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream bind9 package and not the bind9 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of service (infinite loop) via a query for an RRSIG record whose answer is not in the cache, which causes BIND to repeatedly send RRSIG queries to the authoritative servers.

CVSS Scores

version 3.1
Expand this section

NVD

Recommended
3.7 low
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    High
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    None
  • Scope (S)
    Unchanged
  • Confidentiality (C)
    None
  • Integrity (I)
    None
  • Availability (A)
    Low