PT-2005-1158 · Isc+1 · Bind+1
Joao Damas
·
Publicado
2005-01-29
·
Atualizado
2017-07-11
·
CVE-2005-0034
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
BIND version 9.3.0
Description
The issue is caused by an "incorrect assumption" in the
authvalidated validator function when DNSSEC is enabled. This allows remote attackers to cause a denial of service, resulting in the named server exiting, by sending crafted DNS packets that cause an internal consistency test to fail.Recommendations
For BIND version 9.3.0, consider disabling DNSSEC until a patch is available to prevent the denial of service. Additionally, restrict access to the
authvalidated validator function to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bind
Bind Server