CVE-2011-2464
published 2011-07-08CVE-2011-2464: Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial…
PriorityP431medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
19.27%
97.0th percentile
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.1.dfsg-1 (bookworm) | bind9 1:9.8.1.dfsg-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.8.1.dfsg-1 | 1:9.8.1.dfsg-1 |
| isc | bind9 | >= 0 < 1:9.8.1.dfsg-1 | 1:9.8.1.dfsg-1 |
| isc | bind9 | >= 0 < 1:9.8.1.dfsg-1 | 1:9.8.1.dfsg-1 |
| isc | bind9 | >= 0 < 1:9.8.1.dfsg-1 | 1:9.8.1.dfsg-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0HIGH
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-11:03.bind: Remote packet Denial of Service against named(8) servers
bsd_advisories·2011-09-28·CVSS 5.0
CVE-2011-2464 [MEDIUM] FreeBSD-SA-11:03.bind: Remote packet Denial of Service against named(8) servers
FreeBSD-SA-11:03.bind Security Advisory
The FreeBSD Project
Topic: Remote packet Denial of Service against named(8) servers
Category: contrib
Module: bind
Announced: 2011-09-28
Credits: Roy Arends
Affects: 8.2-STABLE after 2011-05-28 and prior to the correction date
Corrected: 2011-07-06 00:50:54 UTC (RELENG_8, 8.2-STABLE)
CVE Name: CVE-2011-2464
Note: This advisory concerns a vulnerability which existed only in
the FreeBSD 8-STABLE branch and was fixed over two months prior to the
date of this advisory.
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Inte
Ubuntu
Bind vulnerability
vendor_ubuntu·2011-07-05
CVE-2011-2464 Bind vulnerability
Title: Bind vulnerability
Summary: An attacker could send crafted input to Bind and cause it to crash.
It was discovered that Bind incorrectly handled certain specially crafted
packets. A remote attacker could use this flaw to cause Bind to stop
responding, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Specially constructed packet will cause named to exit
vendor_redhat·2011-07-05·CVSS 5.0
CVE-2011-2464 [MEDIUM] bind: Specially constructed packet will cause named to exit
bind: Specially constructed packet will cause named to exit
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2011-2464: bind9 - Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before...
vendor_debian·2011·CVSS 5.0
CVE-2011-2464 [MEDIUM] CVE-2011-2464: bind9 - Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before...
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg-1)
bullseye: resolved (fixed in 1:9.8.1.dfsg-1)
forky: resolved (fixed in 1:9.8.1.dfsg-1)
sid: resolved (fixed in 1:9.8.1.dfsg-1)
trixie: resolved (fixed in 1:9.8.1.dfsg-1)
GHSA
GHSA-pgw8-84wx-gr5w: Unspecified vulnerability in ISC BIND 9 9
ghsa_unreviewed·2022-05-14
CVE-2011-2464 [MEDIUM] GHSA-pgw8-84wx-gr5w: Unspecified vulnerability in ISC BIND 9 9
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
OSV
CVE-2011-2464: Unspecified vulnerability in ISC BIND 9 9
osv·2011-07-08·CVSS 5.0
CVE-2011-2464 [MEDIUM] CVE-2011-2464: Unspecified vulnerability in ISC BIND 9 9
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry
bugzilla·2011-11-16·CVSS 4.3
CVE-2011-4313 [MEDIUM] CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry
CVE-2011-4313 bind: Remote denial of service against recursive servers via logging negative cache entry
A denial of service flaw was found in the way bind, a Berkeley Internet Name Domain (BIND) Domain Name System (DNS) server, performed processing of recursive queries for negative cache entries. A remote attacker could provide a specially-crafted DNS query, forcing the named server to process and log the error message, leading to named server crash. A different vulnerability than CVE-2009-0696 and CVE-2011-2464.
References:
[1] http://www.isc.org/software/bind/advisories/cve-2011-tbd
Discussion:
Created bind tracking bugs for this issue
Affects: fedora-all [bug 754509]
---
This is CVE-2011-4313.
---
*** Bug 754494 has been marked as a duplicate of this bug. ***
---
Any ETA for
Bugzilla
CVE-2011-2464 CVE-2011-2465 bind various flaws [fedora-15]
bugzilla·2011-07-05·CVSS 5.0
CVE-2011-2464 [MEDIUM] CVE-2011-2464 CVE-2011-2465 bind various flaws [fedora-15]
CVE-2011-2464 CVE-2011-2465 bind various flaws [fedora-15]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=718966
Please note: this issue affects multiple supported versi
Bugzilla
CVE-2011-2464 bind: Specially constructed packet will cause named to exit
bugzilla·2011-07-05·CVSS 5.0
CVE-2011-2464 [MEDIUM] CVE-2011-2464 bind: Specially constructed packet will cause named to exit
CVE-2011-2464 bind: Specially constructed packet will cause named to exit
A specially crafted packet can cause named process to exit, affecting
DNS services
Discussion:
The Red Hat Security Response Team is aware of the accidental disclosure of the ISC security advisories. We are working to find out more about the vulnerabilities addressed.
Reference:
http://risky.biz/auscert-bind
http://pastebin.com/9NUt8Pk0
---
http://article.gmane.org/gmane.comp.security.oss.general/5415
---
Upstream advisory:
http://www.isc.org/software/bind/advisories/cve-2011-2464
---
Created attachment 511313
bind 9.7.3 P1 -> P3 diff
Comment / header changes excluded.
---
Created attachment 511315
bind 9.8.0 P2 -> P4 diff
---
Created attachment 511316
bind 9.8.0 P2 -> P4 diff
Same as comment #6, remo
http://blogs.oracle.com/sunsecurity/entry/cve_2011_2464_remote_denialhttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062522.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062846.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00006.htmlhttp://marc.info/?l=bugtraq&m=131983337229394&w=2http://osvdb.org/73605http://secunia.com/advisories/45082http://secunia.com/advisories/45089http://secunia.com/advisories/45143http://secunia.com/advisories/45177http://secunia.com/advisories/45185http://secunia.com/advisories/45223http://secunia.com/advisories/45410http://secunia.com/advisories/45412http://support.apple.com/kb/HT5002http://www.debian.org/security/2011/dsa-2272http://www.isc.org/software/bind/advisories/cve-2011-2464http://www.kb.cert.org/vuls/id/142646http://www.mandriva.com/security/advisories?name=MDVSA-2011:115http://www.redhat.com/support/errata/RHSA-2011-0926.htmlhttp://www.securityfocus.com/archive/1/518749/100/0/threadedhttp://www.securityfocus.com/bid/48566http://www.securitytracker.com/id?1025742http://www.slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.377171https://exchange.xforce.ibmcloud.com/vulnerabilities/68375https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13997https://www.ubuntu.com/usn/USN-1163-1/http://blogs.oracle.com/sunsecurity/entry/cve_2011_2464_remote_denialhttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062522.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062846.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00006.htmlhttp://marc.info/?l=bugtraq&m=131983337229394&w=2http://osvdb.org/73605http://secunia.com/advisories/45082http://secunia.com/advisories/45089http://secunia.com/advisories/45143http://secunia.com/advisories/45177http://secunia.com/advisories/45185http://secunia.com/advisories/45223http://secunia.com/advisories/45410http://secunia.com/advisories/45412http://support.apple.com/kb/HT5002http://www.debian.org/security/2011/dsa-2272http://www.isc.org/software/bind/advisories/cve-2011-2464http://www.kb.cert.org/vuls/id/142646http://www.mandriva.com/security/advisories?name=MDVSA-2011:115http://www.redhat.com/support/errata/RHSA-2011-0926.htmlhttp://www.securityfocus.com/archive/1/518749/100/0/threadedhttp://www.securityfocus.com/bid/48566http://www.securitytracker.com/id?1025742http://www.slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.377171https://exchange.xforce.ibmcloud.com/vulnerabilities/68375https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13997https://www.ubuntu.com/usn/USN-1163-1/
2011-07-08
Published