Multiple.Products.Infinitely.Delegating.Name.Servers.DoS

description-logoDescription

This indicates an attempt to exploit a Denial of Service vulnerability in Multiple DNS Server applications.
The vulnerability is due to a validation error when the vulnerable software handles a maliciously crafted DNS query. A remote attacker may be able to exploit this to cause a denial of service condition on the affected system.

affected-products-logoAffected Products

PowerDNS PowerDNS Recursor 3.6.1 and eralier
Unbound 1.5.0 and eralier
BIND 9.0.x through 9.8.x
BIND 9.9.0 through 9.9.6
BIND 9.10.0 through 9.10.1

Impact logoImpact

Denial of Service: Remote attackers can crash vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendors
PowerDNS
http://doc.powerdns.com/md/security/powerdns-advisory-2014-02/
Unbound
https://unbound.net/downloads/CVE-2014-8602.txt
BIND9
https://kb.isc.org/article/AA-01216/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)