CVE-2011-1910
published 2011-05-31CVE-2011-1910: Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
24.64%
97.7th percentile
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.1.dfsg-1 (bookworm) | bind9 1:9.8.1.dfsg-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0HIGH
vendor_redhat5.0MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2011-05-30·CVSS 4.3
CVE-2010-3762 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: An attacker could send crafted input to Bind and cause it to crash.
It was discovered that Bind incorrectly handled certain bad signatures if
multiple trust anchors existed for a single zone. A remote attacker could
use this flaw to cause Bind to stop responding, resulting in a denial of
service. This issue only affected Ubuntu 8.04 LTS and 10.04 LTS.
(CVE-2010-3762)
Frank Kloeker and Michael Sinatra discovered that Bind incorrectly handled
certain very large RRSIG RRsets included in negative responses. A remote
attacker could use this flaw to cause Bind to stop responding, resulting in
a denial of service. (CVE-2011-1910)
Instructions: In general, a standard system update will make all the necessary changes.
BSD
FreeBSD-SA-11:02.bind: BIND remote DoS with large RRSIG RRsets and negative caching
bsd_advisories·2011-05-28·CVSS 5.0
CVE-2011-1910 [MEDIUM] FreeBSD-SA-11:02.bind: BIND remote DoS with large RRSIG RRsets and negative caching
FreeBSD-SA-11:02.bind Security Advisory
The FreeBSD Project
Topic: BIND remote DoS with large RRSIG RRsets and negative caching
Category: contrib
Module: bind
Announced: 2011-05-28
Credits: Frank Kloeker, Michael Sinatra.
Affects: All supported versions of FreeBSD.
Corrected: 2011-05-28 00:58:19 UTC (RELENG_7, 7.4-STABLE)
2011-05-28 08:44:39 UTC (RELENG_7_3, 7.3-RELEASE-p6)
2011-05-28 08:44:39 UTC (RELENG_7_4, 7.4-RELEASE-p2)
2011-05-28 00:33:06 UTC (RELENG_8, 8.2-STABLE)
2011-05-28 08:44:39 UTC (RELENG_8_1, 8.1-RELEASE-p4)
2011-05-28 08:44:39 UTC (RELENG_8_2, 8.2-RELEASE-p2)
CVE Name: CVE-2011-1910
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND
Red Hat
bind: Large RRSIG RRsets and Negative Caching can crash named
vendor_redhat·2011-05-26·CVSS 5.0
CVE-2011-1910 [MEDIUM] bind: Large RRSIG RRsets and Negative Caching can crash named
bind: Large RRSIG RRsets and Negative Caching can crash named
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
Statement: This issue did not affect bind packages shipped with Red Hat Enterprise Linux 4 and 5. It affected bind97 packages shipped with Red Hat Enterprise Linux 5 and bind packages shipped with Red Hat Enterprise Linux 6.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2011-1910: bind9 - Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2...
vendor_debian·2011·CVSS 5.0
CVE-2011-1910 [MEDIUM] CVE-2011-1910: bind9 - Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2...
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg-1)
bullseye: resolved (fixed in 1:9.8.1.dfsg-1)
forky: resolved (fixed in 1:9.8.1.dfsg-1)
sid: resolved (fixed in 1:9.8.1.dfsg-1)
trixie: resolved (fixed in 1:9.8.1.dfsg-1)
GHSA
GHSA-3wf6-qrm5-g4cj: Off-by-one error in named in ISC BIND 9
ghsa_unreviewed·2022-05-13
CVE-2011-1910 [MEDIUM] GHSA-3wf6-qrm5-g4cj: Off-by-one error in named in ISC BIND 9
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
OSV
CVE-2011-1910: Off-by-one error in named in ISC BIND 9
osv·2011-05-31·CVSS 5.0
CVE-2011-1910 [MEDIUM] CVE-2011-1910: Off-by-one error in named in ISC BIND 9
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061405.htmlhttp://marc.info/?l=bugtraq&m=142180687100892&w=2http://osvdb.org/72540http://secunia.com/advisories/44677http://secunia.com/advisories/44719http://secunia.com/advisories/44741http://secunia.com/advisories/44744http://secunia.com/advisories/44758http://secunia.com/advisories/44762http://secunia.com/advisories/44783http://secunia.com/advisories/44929http://security.freebsd.org/advisories/FreeBSD-SA-11:02.bind.aschttp://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.685026http://support.apple.com/kb/HT5002http://www.debian.org/security/2011/dsa-2244http://www.kb.cert.org/vuls/id/795694http://www.mandriva.com/security/advisories?name=MDVSA-2011:104http://www.redhat.com/support/errata/RHSA-2011-0845.htmlhttp://www.securityfocus.com/bid/48007http://www.securitytracker.com/id?1025572https://bugzilla.redhat.com/show_bug.cgi?id=708301https://hermes.opensuse.org/messages/8699912https://www.isc.org/software/bind/advisories/cve-2011-1910http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061405.htmlhttp://marc.info/?l=bugtraq&m=142180687100892&w=2http://osvdb.org/72540http://secunia.com/advisories/44677http://secunia.com/advisories/44719http://secunia.com/advisories/44741http://secunia.com/advisories/44744http://secunia.com/advisories/44758http://secunia.com/advisories/44762http://secunia.com/advisories/44783http://secunia.com/advisories/44929http://security.freebsd.org/advisories/FreeBSD-SA-11:02.bind.aschttp://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.685026http://support.apple.com/kb/HT5002http://www.debian.org/security/2011/dsa-2244http://www.kb.cert.org/vuls/id/795694http://www.mandriva.com/security/advisories?name=MDVSA-2011:104http://www.redhat.com/support/errata/RHSA-2011-0845.htmlhttp://www.securityfocus.com/bid/48007http://www.securitytracker.com/id?1025572https://bugzilla.redhat.com/show_bug.cgi?id=708301https://hermes.opensuse.org/messages/8699912https://www.isc.org/software/bind/advisories/cve-2011-1910
2011-05-31
Published