Lucene search

K
freebsdFreeBSD4CCEE784-A721-11E0-89B4-001EC9578670
HistoryJul 05, 2011 - 12:00 a.m.

BIND -- Remote DoS with certain RPZ configurations

2011-07-0500:00:00
vuxml.freebsd.org
17

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

EPSS

0.175

Percentile

96.2%

ISC reports:

Two defects were discovered in ISC’s BIND 9.8 code. These
defects only affect BIND 9.8 servers which have recursion
enabled and which use a specific feature of the software known
as Response Policy Zones (RPZ) and where the RPZ zone contains
a specific rule/action pattern.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchbind98< 9.8.0.4UNKNOWN

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

EPSS

0.175

Percentile

96.2%