CVE-2011-2465
published 2011-07-08CVE-2011-2465: Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or…
PriorityP415low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
8.88%
94.7th percentile
Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.1.dfsg.P1-1 (bookworm) | bind9 1:9.8.1.dfsg.P1-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.8.1.dfsg.P1-1 | 1:9.8.1.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.8.1.dfsg.P1-1 | 1:9.8.1.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.8.1.dfsg.P1-1 | 1:9.8.1.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.8.1.dfsg.P1-1 | 1:9.8.1.dfsg.P1-1 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: Remote Crash with Certain RPZ Configurations
vendor_redhat·2011-07-05·CVSS 2.6
CVE-2011-2465 [LOW] bind: Remote Crash with Certain RPZ Configurations
bind: Remote Crash with Certain RPZ Configurations
Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.
Statement: Not vulnerable. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 4, 5, or 6 as they did not include support for Response Policy Zones (RPZ).
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-2465: bind9 - Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, ...
vendor_debian·2011·CVSS 2.6
CVE-2011-2465 [LOW] CVE-2011-2465: bind9 - Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, ...
Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-1)
bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-1)
forky: resolved (fixed in 1:9.8.1.dfsg.P1-1)
sid: resolved (fixed in 1:9.8.1.dfsg.P1-1)
trixie: resolved (fixed in 1:9.8.1.dfsg.P1-1)
GHSA
GHSA-mq9v-93wj-m5jw: Unspecified vulnerability in ISC BIND 9 9
ghsa_unreviewed·2022-05-14
CVE-2011-2465 [LOW] GHSA-mq9v-93wj-m5jw: Unspecified vulnerability in ISC BIND 9 9
Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.
OSV
CVE-2011-2465: Unspecified vulnerability in ISC BIND 9 9
osv·2011-07-08·CVSS 2.6
CVE-2011-2465 [LOW] CVE-2011-2465: Unspecified vulnerability in ISC BIND 9 9
Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2464 CVE-2011-2465 bind various flaws [fedora-15]
bugzilla·2011-07-05·CVSS 5.0
CVE-2011-2464 [MEDIUM] CVE-2011-2464 CVE-2011-2465 bind various flaws [fedora-15]
CVE-2011-2464 CVE-2011-2465 bind various flaws [fedora-15]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=718966
Please note: this issue affects multiple supported versi
Bugzilla
CVE-2011-2465 bind: Remote Crash with Certain RPZ Configurations [fedora-rawhide]
bugzilla·2011-07-05·CVSS 2.6
CVE-2011-2465 [LOW] CVE-2011-2465 bind: Remote Crash with Certain RPZ Configurations [fedora-rawhide]
CVE-2011-2465 bind: Remote Crash with Certain RPZ Configurations [fedora-rawhide]
fedora-rawhide tracking bug for bind: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed in bind-9.8.0-7.P4.fc16
Bugzilla
CVE-2011-2465 bind: Remote Crash with Certain RPZ Configurations
bugzilla·2011-07-05·CVSS 2.6
CVE-2011-2465 [LOW] CVE-2011-2465 bind: Remote Crash with Certain RPZ Configurations
CVE-2011-2465 bind: Remote Crash with Certain RPZ Configurations
A defect was bound in certain versions of bind, which causes the "named"
process to exit when configured with certain RPZ configurations
Discussion:
The Red Hat Security Response Team is aware of the accidental disclosure of the ISC security advisories. We are working to find out more about the vulnerabilities addressed.
Reference:
http://risky.biz/auscert-bind
http://pastebin.com/9NUt8Pk0
---
http://article.gmane.org/gmane.comp.security.oss.general/5415
---
Upstream advisory:
http://www.isc.org/software/bind/advisories/cve-2011-2465
---
Statement:
Not vulnerable. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 4, 5, or 6 as they did not include support for Response Policy Zo
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062522.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00002.htmlhttp://osvdb.org/73604http://secunia.com/advisories/45185http://www.isc.org/software/bind/advisories/cve-2011-2465http://www.kb.cert.org/vuls/id/137968http://www.securityfocus.com/archive/1/518750/100/0/threadedhttp://www.securityfocus.com/bid/48565http://www.securitytracker.com/id?1025743https://exchange.xforce.ibmcloud.com/vulnerabilities/68374http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062522.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00002.htmlhttp://osvdb.org/73604http://secunia.com/advisories/45185http://www.isc.org/software/bind/advisories/cve-2011-2465http://www.kb.cert.org/vuls/id/137968http://www.securityfocus.com/archive/1/518750/100/0/threadedhttp://www.securityfocus.com/bid/48565http://www.securitytracker.com/id?1025743https://exchange.xforce.ibmcloud.com/vulnerabilities/68374
2011-07-08
Published