Vulnerability identifier: #VU4347
Vulnerability risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-20
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
ISC BIND
Server applications /
DNS servers
Vendor: ISC
Description
The vulnerability allows a remote attacker to cause denial of service conditions.
The vulnerability exists due to assertion failure when processing DNS responses. A remote attacker can send a malformed response to an RTYPE ANY query, trigger assertion failure and cause denial of service.
Successful exploitation of the vulnerability will result in DoS attack against vulnerable application.
Mitigation
The vendor has issued the following versions to address this vulnerability: 9.9.9-P5, 9.10.4-P5, 9.11.0-P2 or 9.9.9-S7.
Vulnerable software versions
ISC BIND: 9.4.0 - 9.11.0-P1
External links
http://kb.isc.org/article/AA-01439
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.