Degraded Performance in BIND Due to Large DNS Caches

CVE-2024-1737

7.5HIGH

Key Information

Vendor
Isc
Status
Bind 9
Vendor
CVE Published:
23 July 2024

Badges

📰 News Worthy

Summary

Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.4-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.

Affected Version(s)

BIND 9 9.11.0 <= 9.11.37

BIND 9 9.16.0 <= 9.16.50

BIND 9 9.18.0 <= 9.18.27

News Articles

Ενημερώσεις BIND διορθώνουν τέσσερα σοβαρά σφάλματα DoS

Η Internet Systems Consortium (ISC) κυκλοφόρησε ενημερώσεις ασφαλείας για το BIND που αντιμετωπίζουν σοβαρά σφάλματα DoS.

5 months ago

BIND updates fix high-severity DoS bugs in the DNS software suite

The Internet Systems Consortium (ISC) released BIND security updates that fixed remotely exploitable DoS bugs in the DNS software suite.

5 months ago

IT-Sicherheit: UNIX und Windows bedroht - Update für IT-Sicherheitswarnung zu Internet Systems Consortium BIND (Risiko: mittel)

Eine für Internet Systems Consortium BIND herausgegebene Sicherheitswarnung hat vom BSI ein Update erhalten. Welche Produkte von der Sicherheitslücke betroffen sind, lesen Sie hier auf news.de.

5 months ago

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by Linux Security

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database4 News Article(s)

Credit

ISC would like to thank Toshifumi Sakaguchi for bringing this vulnerability to our attention.
.