PT-2002-1454 · Isc+1 · Isc Bind 9+1

Published

2002-06-18

·

Updated

2008-09-10

·

CVE-2002-0400

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ISC BIND 9 versions prior to 9.2.1
Description A logic error exists within the dns message findtype() routine that may allow remote attackers to cause the server program (named) to fail and shutdown. The issue arises when the rdataset parameter to the dns message findtype() function is not properly handled, leading to an error condition that triggers the server to shut down. This requires manual restart of the server.
Recommendations For versions prior to 9.2.1, update to version 9.2.1 or later to resolve the issue. As a temporary workaround, consider implementing measures to prevent malformed DNS packets from reaching the server, such as configuring firewall rules or using a DNS proxy to filter out suspicious traffic.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0400

Affected Products

Bind Server
Isc Bind 9