PT-2002-1454 · Isc+1 · Isc Bind 9+1
Published
2002-06-18
·
Updated
2008-09-10
·
CVE-2002-0400
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
ISC BIND 9 versions prior to 9.2.1
Description
A logic error exists within the dns message findtype() routine that may allow remote attackers to cause the server program (named) to fail and shutdown. The issue arises when the rdataset parameter to the dns message findtype() function is not properly handled, leading to an error condition that triggers the server to shut down. This requires manual restart of the server.
Recommendations
For versions prior to 9.2.1, update to version 9.2.1 or later to resolve the issue. As a temporary workaround, consider implementing measures to prevent malformed DNS packets from reaching the server, such as configuring firewall rules or using a DNS proxy to filter out suspicious traffic.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bind Server
Isc Bind 9