7.1
CVSSv2

CVE-2011-0414

Published: 23/02/2011 Updated: 30/10/2018
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

ISC BIND 9.7.1 up to and including 9.7.2-P3, when configured as an authoritative server, allows remote malicious users to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 9.7.1

isc bind 9.7.2

Vendor Advisories

It was discovered that Bind incorrectly handled IXFR transfers and dynamic updates while under heavy load when used as an authoritative server A remote attacker could use this flaw to cause Bind to stop responding, resulting in a denial of service ...
Debian Bug report logs - #601830 bind9 freezes every now and then Package: bind9; Maintainer for bind9 is Debian DNS Team <team+dns@trackerdebianorg>; Source for bind9 is src:bind9 (PTS, buildd, popcon) Reported by: Benoit Panizzon <debianbug@exp1210spamwoodych> Date: Sat, 30 Oct 2010 07:21:04 UTC Severity: im ...
It was discovered that BIND, a DNS server, contains a race condition when processing zones updates in an authoritative server, either through dynamic DNS updates or incremental zone transfer (IXFR) Such an update while processing a query could result in deadlock and denial of service (CVE-2011-0414) In addition, this security update addresses a d ...