Mailing List

Name:

Email:

[SingCERT] ISC BIND Denial of Service Vulnerabilities

Attention: open in a new window. PDFPrintE-mail

[ Summary ]

Two vulnerabilities CVE-2011-2464 and CVE-2011-2465 have been reported in ISC BIND.

 
[ Affected Systems ]

  • CVE-2011-2464 affects versions 9.6.3, 9.6-ESV-R4, 9.6-ESV-R4-P1, 9.6-ESV-R5b1 9.7.0, 9.7.0-P1, 9.7.0-P2, 9.7.1, 9.7.1-P1, 9.7.1-P2, 9.7.2, 9.7.2-P1, 9.7.2-P2, 9.7.2-P3, 9.7.3, 9.7.3-P1, 9.7.3-P2, 9.7.4b1 9.8.0, 9.8.0-P1, 9.8.0-P2, 9.8.0-P3, 9.8.1b1.
  • CVE-2011-2465 affects versions 9.8.0, 9.8.0-P1, 9.8.0-P2 and 9.8.1b1 Other versions of BIND 9 not listed here are not vulnerable to this problem.

[ Impact Analysis ]

These vulnerabilities can be exploited to cause a Denial of Service condition.


[ Solution/Workaround ]

Upgrade to version 9.6-ESV-R4-P3, 9.7.3-P3 or 9.8.0-P4.


[ Reference ]