CERT-In Vulnerability Note
CIVN-2024-0053
Multiple Vulnerabilities in ISC BIND
Original Issue Date:February 20, 2024
Severity Rating: HIGH
Software Affected
- BIND version 9.0.0 - 9.16.46
- BIND version 9.18.0 - 9.18.22
- BIND version 9.19.0 - 9.19.20
- BIND Supported Preview Edition version 9.9.3-S1 - 9.16.46-S1
- BIND Supported Preview Edition version 9.18.11-S1 - 9.18.22-S1
Overview
Multiple vulnerabilities have been reported in the Internet Systems Consortium (ISC) BIND software, which could allow a remote attacker to cause denial of service condition on the targeted system.
Description
These vulnerabilities exist in ISC BIND due to a flaw in query-handling code, when enabling both DNS64 and serve-stale, excessive CPU load, out-of-memory condition, improper restriction of DNSSEC verification complexity and CPU exhaustion on a DNSSEC-validating resolver.
Successful exploitation of these vulnerabilities could allow a remote attacker to cause denial of service condition on the targeted System.
Solution
Apply appropriate updates as mentioned in the ISC Security Bulletin:
https://kb.isc.org/v1/docs/cve-2023-4408
https://kb.isc.org/v1/docs/cve-2023-5517
https://kb.isc.org/v1/docs/cve-2023-5679
https://kb.isc.org/v1/docs/cve-2023-5680
https://kb.isc.org/v1/docs/cve-2023-6516
https://kb.isc.org/v1/docs/cve-2023-50387
https://kb.isc.org/v1/docs/cve-2023-50868
Vendor Information
ISC
https://kb.isc.org/v1/docs/cve-2023-4408
https://kb.isc.org/v1/docs/cve-2023-5517
https://kb.isc.org/v1/docs/cve-2023-5679
https://kb.isc.org/v1/docs/cve-2023-5680
https://kb.isc.org/v1/docs/cve-2023-6516
https://kb.isc.org/v1/docs/cve-2023-50387
https://kb.isc.org/v1/docs/cve-2023-50868
References
ISC
https://kb.isc.org/v1/docs/cve-2023-4408
https://kb.isc.org/v1/docs/cve-2023-5517
https://kb.isc.org/v1/docs/cve-2023-5679
https://kb.isc.org/v1/docs/cve-2023-5680
https://kb.isc.org/v1/docs/cve-2023-6516
https://kb.isc.org/v1/docs/cve-2023-50387
https://kb.isc.org/v1/docs/cve-2023-50868
CVE Name
CVE-2023-4408
CVE-2023-5517
CVE-2023-5679
CVE-2023-5680
CVE-2023-6516
CVE-2023-50387
CVE-2023-50868
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|