5
CVSSv2

CVE-2011-2464

Published: 08/07/2011 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Unspecified vulnerability in ISC BIND 9 9.6.x prior to 9.6-ESV-R4-P3, 9.7.x prior to 9.7.3-P3, and 9.8.x prior to 9.8.0-P4 allows remote malicious users to cause a denial of service (named daemon crash) via a crafted UPDATE request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 9.6.3

isc bind 9.6.1

isc bind 9.6.2

isc bind 9.6.0

isc bind 9.6

isc bind 9.7.0

isc bind 9.7.2

isc bind 9.7.3

isc bind 9.7.1

isc bind 9.7.2b1

isc bind 9.8.0

isc bind 9.8.1

Vendor Advisories

An attacker could send crafted input to Bind and cause it to crash ...
It was discovered that BIND, a DNS server, does not correctly process certain UPDATE requests, resulting in a server crash and a denial of service This vulnerability affects BIND installations even if they do not actually use dynamic DNS updates For the oldstable distribution (lenny), this problem has been fixed in version 1:96ESVR4+dfsg-0+len ...

References

NVD-CWE-noinfohttp://www.securityfocus.com/bid/48566http://www.securitytracker.com/id?1025742http://www.kb.cert.org/vuls/id/142646http://www.debian.org/security/2011/dsa-2272http://secunia.com/advisories/45185http://secunia.com/advisories/45082http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062846.htmlhttp://osvdb.org/73605http://secunia.com/advisories/45223http://www.slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.377171http://secunia.com/advisories/45177http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062522.htmlhttp://www.isc.org/software/bind/advisories/cve-2011-2464http://www.redhat.com/support/errata/RHSA-2011-0926.htmlhttp://secunia.com/advisories/45412http://secunia.com/advisories/45143http://blogs.oracle.com/sunsecurity/entry/cve_2011_2464_remote_denialhttp://secunia.com/advisories/45410http://secunia.com/advisories/45089http://support.apple.com/kb/HT5002http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00006.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:115http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00004.htmlhttp://marc.info/?l=bugtraq&m=131983337229394&w=2https://www.ubuntu.com/usn/USN-1163-1/https://exchange.xforce.ibmcloud.com/vulnerabilities/68375https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13997http://www.securityfocus.com/archive/1/518749/100/0/threadedhttps://usn.ubuntu.com/1163-1/https://nvd.nist.govhttps://www.kb.cert.org/vuls/id/142646