The Wayback Machine - https://web.archive.org/web/20110614112012/http://www.isc.org/advisories/bind

BIND Security Advisories

Large RRSIG RRsets and Negative Caching can crash named

Summary: 
A BIND 9 DNS server set up to be a caching resolver is vulnerable to a user querying a domain with very large resource record sets (RRSets) when trying to negatively cache a response. This can cause the BIND 9 DNS server (named process) to crash.
CVE: 
CVE-2011-1910
CERT: 
VU#795694
Document Version: 
1.3
Posting date: 
26 May 2011
Program Impacted: 
BIND
Versions affected: 
9.4-ESV-R3 and later, 9.6-ESV-R2 and later, 9.6.3, 9.7.1 and later, 9.8.0 and later
Severity: 
High
Exploitable: 
remotely

RRSIG Queries Can Trigger Server Crash When Using Response Policy Zones

Summary: 
When a name server is configured with a response policy zone (RPZ), queries for type RRSIG can trigger a server crash.
CVE: 
CVE-2011-1907
Posting date: 
05 May 2011
Program Impacted: 
BIND
Versions affected: 
9.8.0
Severity: 
High
Exploitable: 
remotely
Attachments

BIND: Server Lockup Upon IXFR or DDNS Update Combined with High Query Rate

Summary: 
When an authoritative server processes a successful IXFR transfer or a dynamic update, there is a small window of time during which the IXFR/update coupled with a query may cause a deadlock to occur.
CVE: 
CVE-2011-0414
CERT: 
VU#559980
Posting date: 
22 Feb 2011
Program Impacted: 
BIND
Versions affected: 
9.7.1-9.7.2-P3
Severity: 
High
Exploitable: 
remotely

BIND: cache incorrectly allows a ncache entry and a rrsig for the same type

Summary: 
Failure to clear existing RRSIG records when a NO DATA is negatively cached could cause subsequent lookups to crash named.
CVE: 
CVE-2010-3613
CERT: 
VU#706148
Posting date: 
01 Dec 2010
Program Impacted: 
BIND
Versions affected: 
9.0.x to 9.7.2-P2, 9.4-ESV to 9.4-ESV-R3, 9.6-ESV to 9.6-ESV-R2
Severity: 
High
Exploitable: 
remotely

BIND: allow-query processed incorrectly

Summary: 
Using "allow-query" in the "options" or "view" statements to restrict access to authoritative zones has no effect.
CVE: 
CVE-2010-3615
CERT: 
VU#510208
Posting date: 
01 Dec 2010
Program Impacted: 
BIND
Versions affected: 
9.7.2-P2
Severity: 
High
Exploitable: 
remotely
Share this