Jump to content
Compatible Support Forums
Sign in to follow this  
news

[SECURITY] [DLA 112-1] bind9 security update

Recommended Posts

Package : bind9

Version : 9.7.3.dfsg-1~squeeze13

CVE ID : CVE-2014-8500

Debian Bug : 772610

 

This update fixes a denial of service vulnerability in BIND, a DNS server.

 

By making use of maliciously-constructed zones or a rogue server, an attacker

could exploit an oversight in the code BIND 9 used to follow delegations in

the Domain Name Service, causing BIND to issue unlimited queries in an attempt

to follow the delegation.

 

This can lead to resource exhaustion and denial of service (up to and

including termination of the named server process).

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×