ISC BIND是美国ISC公司的一套实现了DNS协议的开源软件。 ISC BIND 9.11.3-S1 到 9.11.37-S1、9.16.8-S1 到 9.16.45-S1 以及 9.18.11-S1 到 9.18.21-S1版本存在安全漏洞,该漏洞源于如果解析器缓存存储了大量同名 ECS 记录,则清理该名称的缓存数据库节点可能会严重影响查询性能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-4408 | 7.5 HIGH | Parsing large DNS messages may cause excessive CPU load |
| CVE-2023-5517 | 7.5 HIGH | Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is |
| CVE-2023-5679 | 7.5 HIGH | Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolu |
| CVE-2023-6516 | 7.5 HIGH | Specific recursive query patterns may lead to an out-of-memory condition |
No comments yet