CVE-2011-0414

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.

References

http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html

http://secunia.com/advisories/43439

http://secunia.com/advisories/43443

http://www.debian.org/security/2011/dsa-2208

http://www.isc.org/software/bind/advisories/cve-2011-0414

http://www.kb.cert.org/vuls/id/449980

http://www.kb.cert.org/vuls/id/559980

http://www.securitytracker.com/id?1025110

http://www.ubuntu.com/usn/USN-1070-1

http://www.vupen.com/english/advisories/2011/0466

http://www.vupen.com/english/advisories/2011/0489

https://bugzilla.redhat.com/show_bug.cgi?id=679496

Details

Source: MITRE

Published: 2011-02-23

Updated: 2018-10-30

Type: CWE-399

Risk Information

CVSS v2

Base Score: 7.1

Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (8 total)

IDNameProductFamilySeverity
137170OracleVM 3.3 / 3.4 : bind (OVMSA-2020-0021)NessusOracleVM Local Security Checks
high
99569OracleVM 3.3 / 3.4 : bind (OVMSA-2017-0066)NessusOracleVM Local Security Checks
high
75438openSUSE Security Update : bind (openSUSE-SU-2011:0135-1)NessusSuSE Local Security Checks
high
59629GLSA-201206-01 : BIND: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
53224Debian DSA-2208-1 : bind9 - denial of serviceNessusDebian Local Security Checks
high
5803ISC BIND 9.7.1 - 9.7.2-P3 IXFR /DDNS Update Combinded with High Query Rate DoSNessus Network MonitorDNS Servers
medium
52164Ubuntu 10.10 : bind9 vulnerability (USN-1070-1)NessusUbuntu Local Security Checks
high
52158ISC BIND 9.7.1-9.7.2-P3 IXFR / DDNS Update Combined with High Query Rate DoSNessusDNS
high