ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Feb 23, 2011 |
| Dns Bind | — | Use single worker thread to avoid deadlockUpgrade ISC BIND to latest version | Oct 5, 2011 | Feb 22, 2011 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Feb 23, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 22, 2011 |
| Suse | — | Upgrade libbind9-160Upgrade bind-modules-ldapUpgrade libisccfg160Upgrade bind-docUpgrade python-bindUpgrade libdns169Upgrade libisc166-32bitUpgrade bind-utilsUpgrade bind-libs-32bitUpgrade libisc166Upgrade liblwres160Upgrade bind-chrootenvUpgrade bind-modules-sqlite3Upgrade bind-modules-mysqlUpgrade bind-develUpgrade bind-modules-perlUpgrade python3-bindUpgrade libisccc160Upgrade bind-libsUpgrade bind-modules-genericUpgrade libirs160Upgrade bindUpgrade libirs-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libdns66 | Nov 8, 2024 | Feb 23, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub