Lucene search

K
f5F5F5:K000135504
HistoryJul 17, 2023 - 12:00 a.m.

K000135504 : BIND vulnerability CVE-2023-2911

2023-07-1700:00:00
my.f5.com
11
bind
vulnerability
cve-2023-2911
resolver
stack overflow
f5 products

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

49.4%

Security Advisory Description

If the recursive-clients quota is reached on a BIND 9 resolver configured with both stale-answer-enable yes; and stale-answer-client-timeout 0;, a sequence of serve-stale-related lookups could cause named to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33 through 9.16.41, 9.18.7 through 9.18.15, 9.16.33-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1. (CVE-2023-2911)

Impact

There is no impact; F5 products are not affected by these vulnerabilities.