PT-2023-6785 · Isc+12 · Bind 9+12

Anat Bremler-Barr

+3

·

Publicado

2023-06-14

·

Atualizado

2024-10-03

·

CVE-2023-2828

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.11.0 through 9.16.41 BIND 9 versions 9.18.0 through 9.18.15 BIND 9 versions 9.19.0 through 9.19.13 BIND 9 versions 9.11.3-S1 through 9.16.41-S1 BIND 9 versions 9.18.11-S1 through 9.18.15-S1
Description The effectiveness of the cache-cleaning algorithm used in named can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured max-cache-size limit to be significantly exceeded. This can lead to a denial of service, caused by a flaw that allows the named's configured cache size limit to be significantly exceeded, potentially exhausting all memory on the host.
Recommendations For BIND 9 versions 9.11.0 through 9.16.41, update to a version that includes a fix for this issue. For BIND 9 versions 9.18.0 through 9.18.15, update to a version that includes a fix for this issue. For BIND 9 versions 9.19.0 through 9.19.13, update to a version that includes a fix for this issue. For BIND 9 versions 9.11.3-S1 through 9.16.41-S1, update to a version that includes a fix for this issue. For BIND 9 versions 9.18.11-S1 through 9.18.15-S1, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the named instance to minimize the risk of exploitation.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:4099
ALSA-2023:4100
ALSA-2023:4102
ALT-PU-2023-2044
ALT-PU-2023-2102
ALT-PU-2024-1988
ALT-PU-2024-9772
ALT-PU-2024-9774
AZL-27203
AZL-27238
BDU:2023-07642
CESA-2023_4100
CESA-2023_4102
CESA-2023_4152
CVE-2023-2828
DLA-3498-1
DSA-5439-1
OESA-2023-1384
OESA-2023-1505
OPENSUSE-SU-2023_2954-1
OPENSUSE-SU-2024:13015-1
RHSA-2023:4005
RHSA-2023:4037
RHSA-2023:4099
RHSA-2023:4100
RHSA-2023:4101
RHSA-2023:4102
RHSA-2023:4152
RHSA-2023:4153
RHSA-2023:4154
RHSA-2023:4332
RHSA-2023_4099
RHSA-2023_4100
RHSA-2023_4102
RHSA-2023_4152
RLSA-2023:4099
RLSA-2023:4100
RLSA-2023:4102
ROSA-SA-2023-2279
ROSA-SA-2024-2489
SUSE-SU-2023:2667-1
SUSE-SU-2023:2789-1
SUSE-SU-2023:2793-1
SUSE-SU-2023:2794-1
SUSE-SU-2023:2836-1
SUSE-SU-2023:2954-1
SUSE-SU-2023_2667-1
SUSE-SU-2023_2789-1
SUSE-SU-2023_2793-1
SUSE-SU-2023_2794-1
SUSE-SU-2023_2836-1
SUSE-SU-2023_2954-1
USN-6183-1
USN-6183-2

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu