2.6 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:H/Au:N/C:N/I:N/A:P
8 High
AI Score
Confidence
High
0.042 Low
EPSS
Percentile
92.3%
BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of service (infinite loop) via a query for an RRSIG record whose answer is not in the cache, which causes BIND to repeatedly send RRSIG queries to the authoritative servers.
lists.fedoraproject.org/pipermail/package-announce/2010-July/044445.html
lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html
secunia.com/advisories/40652
secunia.com/advisories/40709
www.isc.org/software/bind/advisories/cve-2010-0213
www.kb.cert.org/vuls/id/211905
www.securityfocus.com/bid/41730
www.securitytracker.com/id?1024217
www.vupen.com/english/advisories/2010/1884