CVE-2011-1907Reachable Assertion in Bind

CWE-3997 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
22.4%
top 4.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 9
Latest updateMay 14

Description

ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG query.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianisc/bind9< 1:9.8.1.dfsg.P1-1+3
NVDisc/bind9.8.0

🔴Vulnerability Details

3
GHSA
GHSA-2j8v-wf82-m8qv: ISC BIND 92022-05-14
CVEList
CVE-2011-1907: ISC BIND 92011-05-09
OSV
CVE-2011-1907: ISC BIND 92011-05-09

📋Vendor Advisories

2
Red Hat
bind: RRSIG queries can trigger server crash when using Response Policy Zones (RPZ)2011-05-05
Debian
CVE-2011-1907: bind9 - ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replaceme...2011

💬Community

1
Bugzilla
CVE-2011-1907 bind: RRSIG queries can trigger server crash when using Response Policy Zones (RPZ)2011-05-06
CVE-2011-1907 — Reachable Assertion in ISC Bind | cvebase