漏洞标题
使用 nxdomain-redirect 功能处理某些查询时,可能会导致 db.c 中的 REQUIRE 断言失败
漏洞描述信息
使用 nxdomain-redirect 功能处理某些查询时,可能会导致 db.c 中的 REQUIRE 断言失败
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
漏洞类别
N/A
漏洞标题
An error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.c
漏洞描述信息
An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the "nxdomain-redirect" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type "redirect" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
ISC BIND 安全漏洞
漏洞描述信息
ISC BIND是美国Internet Systems Consortium(ISC)公司所维护的一套实现了DNS协议的开源软件。 ISC BIND中对查询的处理存在远程拒绝服务漏洞。攻击者可通过返回一个特制的查询响应利用该漏洞造成拒绝服务。以下版本受到影响:ISC BIND 9.9.8-S1版本至9.9.8-S3版本,9.9.9-S1版本至9.9.9-S6版本,9.11.0版本至9.11.0 P1版本。
CVSS信息
N/A
漏洞类别
代码问题