Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: ISC describe DNS crash bug analysis - SANS Internet Storm Center SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
ISC describe DNS crash bug analysis

You may recall in mid November that it was reported  that DNS resolvers across the Internet were crashing. This was classified as CVE-2011-4313.

Well, the developers of BIND at the Internet Systems Consortium have announced their findings into the issue.

They say that:

We have confirmed that it was triggered by an accidental operational error that exposed a previously unknown bug in BIND, causing an internal inconsistency which is effectively prevented by the mitigation patches we have produced and distributed.

They also highlight that this could have been exploited maliciously, so if you are running a version of BIND which is vulnerable to CVE-2011-4313 then they advise you to upgrade.

Steve Hall

ISC Handler.

Stephen

89 Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!