DNS Server Unstable During Malicious DNS Message Flood

CVE-2024-0760
7.5HIGH

Key Information

Vendor
Isc
Status
Bind 9
Vendor
CVE Published:
23 July 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

The vulnerability CVE-2024-0760 affects the DNS server and can cause it to become unstable during a flood of malicious DNS messages over TCP. It impacts BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1. This vulnerability could lead to a denial of service and has been exploited in the wild. Ubuntu has released updated packages to fix the issue, and it is recommended for affected systems to update promptly.

Affected Version(s)

BIND 9 <= 9.18.27

BIND 9 <= 9.19.24

BIND 9 <= 9.18.27-S1

News Articles

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • First article discovered by Linux Security

  • Vulnerability published.

  • Vulnerability Reserved.

  • 👾

    Exploit exists.

Collectors

NVD DatabaseMitre Database4 News Article(s)
.