CERT-In Vulnerability Note
CIVN-2012-0121
ISC BIND DNS64 REQUIRE Assertion Failure Denial of Service Vulnerability
Original Issue Date:December 24, 2012
Severity Rating: HIGH
Systems Affected
- Linux Version 9.8.0 - 9.8.4
- Linux Version 9.9.0 - 9.9.2
Overview
A vulnerability has been reported in ISC BIND, which could be exploited by a remote person to cause a DoS (Denial of Service) attack.
Description
This vulnerability exist in BIND nameservers using the DNS64 IPv6 transition mechanism, which could be exploited by a remote attacker to crash the server with a REQUIRE assertion failure.
Solution
Update to version 9.8.4-P1 or 9.9.2-P1 as mentioned in the advisory
https://kb.isc.org/article/AA-00828
Vendor Information
Internet Systems Consortium
https://kb.isc.org/article/AA-00828
References
Internet Systems Consortium
https://kb.isc.org/article/AA-00828
SecurityTracker
http://securitytracker.com/id/1027835
Secunia
http://secunia.com/advisories/51484
CVE Name
CVE-2012-5688
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|