CVE-2024-0760

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.
Configurations

No configuration.

History

01 Aug 2024, 13:45

Type Values Removed Values Added
CWE CWE-770

31 Jul 2024, 11:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/07/31/2 -

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Un cliente malintencionado puede enviar muchos mensajes DNS a través de TCP, lo que podría provocar que el servidor se vuelva inestable mientras el ataque está en curso. El servidor puede recuperarse una vez que cese el ataque. El uso de ACL no mitigará el ataque. Este problema afecta a las versiones 9.18.1 a 9.18.27, 9.19.0 a 9.19.24 y 9.18.11-S1 a 9.18.27-S1 de BIND 9.

23 Jul 2024, 16:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/07/23/1 -

23 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-23 15:15

Updated : 2024-08-01 13:45


NVD link : CVE-2024-0760

Mitre link : CVE-2024-0760

CVE.ORG link : CVE-2024-0760


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling