PT-2024-5210 · Isc+8 · Bind 9+8
Published
2024-07-10
·
Updated
2025-03-14
·
CVE-2024-0760
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
BIND 9 versions 9.18.1 through 9.18.27
BIND 9 versions 9.19.0 through 9.19.24
BIND 9 versions 9.18.11-S1 through 9.18.27-S1
Description:
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack.
Recommendations:
For BIND 9 versions 9.18.1 through 9.18.27, update to a version outside of this range to resolve the issue.
For BIND 9 versions 9.19.0 through 9.19.24, update to a version outside of this range to resolve the issue.
For BIND 9 versions 9.18.11-S1 through 9.18.27-S1, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting the use of TCP for DNS messages to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Bind 9
Bind Server
Ibm Aix
Linuxmint
Red Os
Suse
Ubuntu