CVE-2011-0414
published 2011-02-23CVE-2011-0414: ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by…
PriorityP434high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
13.60%
96.1th percentile
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.7.3.dfsg-1 (bookworm) | bind9 1:9.7.3.dfsg-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.7.3.dfsg-1 | 1:9.7.3.dfsg-1 |
| isc | bind9 | >= 0 < 1:9.7.3.dfsg-1 | 1:9.7.3.dfsg-1 |
| isc | bind9 | >= 0 < 1:9.7.3.dfsg-1 | 1:9.7.3.dfsg-1 |
| isc | bind9 | >= 0 < 1:9.7.3.dfsg-1 | 1:9.7.3.dfsg-1 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerability
vendor_ubuntu·2011-02-23
CVE-2011-0414 Bind vulnerability
Title: Bind vulnerability
It was discovered that Bind incorrectly handled IXFR transfers and dynamic
updates while under heavy load when used as an authoritative server. A
remote attacker could use this flaw to cause Bind to stop responding,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: named lockup with IXFR or DDNS update and a high query rate
vendor_redhat·2011-02-22·CVSS 7.1
CVE-2011-0414 [HIGH] bind: named lockup with IXFR or DDNS update and a high query rate
bind: named lockup with IXFR or DDNS update and a high query rate
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
Statement: Not vulnerable. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2011-0414: bind9 - ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, all...
vendor_debian·2011·CVSS 7.1
CVE-2011-0414 [HIGH] CVE-2011-0414: bind9 - ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, all...
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
Scope: local
bookworm: resolved (fixed in 1:9.7.3.dfsg-1)
bullseye: resolved (fixed in 1:9.7.3.dfsg-1)
forky: resolved (fixed in 1:9.7.3.dfsg-1)
sid: resolved (fixed in 1:9.7.3.dfsg-1)
trixie: resolved (fixed in 1:9.7.3.dfsg-1)
GHSA
GHSA-x6p7-4923-38gh: ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2011-0414 [HIGH] GHSA-x6p7-4923-38gh: ISC BIND 9
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
OSV
CVE-2011-0414: ISC BIND 9
osv·2011-02-23·CVSS 7.1
CVE-2011-0414 [HIGH] CVE-2011-0414: ISC BIND 9
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://secunia.com/advisories/43439http://secunia.com/advisories/43443http://www.debian.org/security/2011/dsa-2208http://www.isc.org/software/bind/advisories/cve-2011-0414http://www.kb.cert.org/vuls/id/449980http://www.kb.cert.org/vuls/id/559980http://www.securitytracker.com/id?1025110http://www.ubuntu.com/usn/USN-1070-1http://www.vupen.com/english/advisories/2011/0466http://www.vupen.com/english/advisories/2011/0489https://bugzilla.redhat.com/show_bug.cgi?id=679496http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://secunia.com/advisories/43439http://secunia.com/advisories/43443http://www.debian.org/security/2011/dsa-2208http://www.isc.org/software/bind/advisories/cve-2011-0414http://www.kb.cert.org/vuls/id/449980http://www.kb.cert.org/vuls/id/559980http://www.securitytracker.com/id?1025110http://www.ubuntu.com/usn/USN-1070-1http://www.vupen.com/english/advisories/2011/0466http://www.vupen.com/english/advisories/2011/0489https://bugzilla.redhat.com/show_bug.cgi?id=679496
2011-02-23
Published