CyberzSOC

Publication detail
← Back to advisories & guidance

ISC Releases Security Advisories for BIND 9 ↗ source

July 24, 2024 CISA Alert

Summary

A cyber threat actor could exploit one of these vulnerabilities to cause a denial-of-service condition. CVE-2024-4076: Assertion failure when serving both stale cache data and authoritative zone content CVE-2024-1975: SIG(0) can be used to exhaust CPU resources CVE-2024-1737: BIND’s database will be slow if a very large number of RRs exist at the same name CVE-2024-0760: A flood of DNS messages over TCP may make the server unstable This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-0760 7.5 High ISC BIND 9 A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server…
CVE-2024-1737 7.5 High ISC BIND 9 Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded p…
CVE-2024-1975 7.5 High ISC BIND 9 If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in ca…
CVE-2024-4076 7.5 High ISC BIND 9 Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. Thi…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.