PT-2024-5210 · Isc+8 · Bind 9+8

Published

2024-07-10

·

Updated

2025-03-14

·

CVE-2024-0760

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: BIND 9 versions 9.18.1 through 9.18.27 BIND 9 versions 9.19.0 through 9.19.24 BIND 9 versions 9.18.11-S1 through 9.18.27-S1
Description: A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack.
Recommendations: For BIND 9 versions 9.18.1 through 9.18.27, update to a version outside of this range to resolve the issue. For BIND 9 versions 9.19.0 through 9.19.24, update to a version outside of this range to resolve the issue. For BIND 9 versions 9.18.11-S1 through 9.18.27-S1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the use of TCP for DNS messages to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-12002
ALT-PU-2024-13685
AZL-46972
BDU:2024-05771
CVE-2024-0760
DSA-5734-1
DSA-5734-2
MGASA-2024-0342
OESA-2024-2014
OESA-2024-2015
OESA-2024-2016
OESA-2024-2017
OPENSUSE-SU-2024:14217-1
SUSE-SU-2024:2636-1
SUSE-SU-2024_2636-1
USN-6909-1

Affected Products

Alt Linux
Astra Linux
Bind 9
Bind Server
Ibm Aix
Linuxmint
Red Os
Suse
Ubuntu