Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Debian: DSA-2560-1 Urgent: bind9 Vulnerability to Denial of Service

debian
Calendar Grey October 20, 2012
Debian Logo
The Debian Security Advisory DSA-2560-1 addresses a flaw in bind9 that can lead to server stalling, linked with DNS response handling.
It was discovered that BIND, a DNS server, hangs while constructing the additional section of a DNS reply, when certain combinations of resource records are present

Summary

It was discovered that BIND, a DNS server, hangs while constructing
the additional section of a DNS reply, when certain combinations of
resource records are present. This vulnerability affects both
recursive and authoritative servers.

For the stable distribution (squeeze), this problem has been fixed in
version 1:9.7.3.dfsg-1~squeeze8.

We recommend that you upgrade your bind9 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: bind9
CVE ID: CVE-2012-5166

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here