FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-2465

This CVE name corresponds to:

Entered Topic
2011-07-05 BIND -- Remote DoS with certain RPZ configurations

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-2465
Phase Assigned(20110606)

Description

Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.

References

Source Reference
BUGTRAQ 20110705 Security Advisory: CVE-2011-2465 ISC BIND 9 Remote Crash with Certain RPZ Configurations
CONFIRM http://www.isc.org/software/bind/advisories/cve-2011-2465
FEDORA FEDORA-2011-9146
SUSE SUSE-SA:2011:029
CERT-VN VU#137968
BID 48565
OSVDB 73604
SECTRACK 1025743
SECUNIA 45185
XF iscbind-rpz-dos(68374)