Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: ISC describe DNS crash bug analysis SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
ISC describe DNS crash bug analysis

You may recall in mid November that it was reported  that DNS resolvers across the Internet were crashing. This was classified as CVE-2011-4313.

Well, the developers of BIND at the Internet Systems Consortium have announced their findings into the issue.

They say that:

We have confirmed that it was triggered by an accidental operational error that exposed a previously unknown bug in BIND, causing an internal inconsistency which is effectively prevented by the mitigation patches we have produced and distributed.

They also highlight that this could have been exploited maliciously, so if you are running a version of BIND which is vulnerable to CVE-2011-4313 then they advise you to upgrade.

Steve Hall

ISC Handler.


89 Posts
Dec 5th 2011

Sign Up for Free or Log In to start participating in the conversation!