PT-2005-1158 · Isc+1 · Bind+1

Joao Damas

·

Publicado

2005-01-29

·

Atualizado

2017-07-11

·

CVE-2005-0034

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions BIND version 9.3.0
Description The issue is caused by an "incorrect assumption" in the authvalidated validator function when DNSSEC is enabled. This allows remote attackers to cause a denial of service, resulting in the named server exiting, by sending crafted DNS packets that cause an internal consistency test to fail.
Recommendations For BIND version 9.3.0, consider disabling DNSSEC until a patch is available to prevent the denial of service. Additionally, restrict access to the authvalidated validator function to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0034

Produtos afetados

Bind
Bind Server