PT-2003-1950 · Isc+1 · Bind+1

Published

2003-12-02

·

Updated

2018-10-30

·

CVE-2003-0914

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ISC BIND versions 8.3.x through 8.3.6 ISC BIND versions 8.4.x through 8.4.2
Description The issue allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL value. To exploit this, an attacker must configure a name server to return authoritative negative responses for a given target domain. The attacker must then convince a victim user to query the maliciously configured name server, which will reply with an authoritative negative response containing a large TTL value. This causes the victim's site, if running a vulnerable version of BIND 8, to cache the negative response, rendering the target domain unreachable until the TTL expires.
Recommendations For ISC BIND versions 8.3.x through 8.3.6, update to version 8.3.7 or later. For ISC BIND versions 8.4.x through 8.4.2, update to version 8.4.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0914
DSA-409

Affected Products

Bind
Bind Server