cbcvebase.
CVE-2012-4244
published 2012-09-14

CVE-2012-4244: ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a…

PriorityP345high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
36.80%
98.3th percentile
ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
debianbind9< bind9 1:9.8.4.dfsg-1 (bookworm)bind9 1:9.8.4.dfsg-1 (bookworm)
debianisc-dhcp< bind9 1:9.8.4.dfsg-1 (bookworm)bind9 1:9.8.4.dfsg-1 (bookworm)
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by a DNS query for a resource record whose RDATA exceeds 65535 bytes, causing an assertion failure and named daemon exit. Monitor for unusually large DNS resource record responses (RDATA > 65535 bytes) in DNS traffic.
  • Attack vector is remote: an attacker can cause a recursive resolver to crash by directing it to query an authoritative server serving an oversized resource record. Detect recursive resolvers querying authoritative servers that return abnormally large RDATA in a single resource record.
  • Authoritative servers are also at risk if a zone file containing an oversized resource record is loaded from disk or via zone transfer. Monitor zone transfer (AXFR/IXFR) traffic for records with RDATA exceeding 65535 bytes.
  • The crash manifests as a REQUIRE exception (assertion failure) in the named process. Monitor system logs for named process exits with assertion/REQUIRE failure messages.
  • ·Affected BIND versions are 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3. Ensure named version is patched to at least these fix versions.
  • ·No workaround is available for this vulnerability; the only mitigation is patching or disabling the BIND name server entirely.

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.