Specially Crafted DNS Data Can Cause a Lockup in named

Summary: 
A nameserver can be locked up if it can be induced to load a specially-crafted combination of resource records.
CVE: 
CVE-2012-5166
Document Version: 
2.0
Posting date: 
09 Oct 2012
Program Impacted: 
BIND
Versions affected: 
Pre-9.6, 9.6-ESV->9.6-ESV-R7-P3, 9.7.0->9.7.6-P3, 9.8.0->9.8.3-P3, 9.9.0->9.9.1-P3
Severity: 
Critical
Exploitable: 
remotely
Description: 

Please see the full advisory at https://kb.isc.org/article/AA-00801

Workarounds: 

Setting the option 'minimal-responses' to 'yes' will prevent the lockup.

Active exploits: 
None known at this time.
Solution: 

Upgrade to the patched version or new release most closely related to your current version of BIND. The patched versions of BIND and new releases can be downloaded from http://www.isc.org/downloads/all.

  • BIND 9 version 9.7.7, 9.7.6-P4
  • BIND 9 version 9.6-ESV-R8, 9.6-ESV-R7-P4
  • BIND 9 version 9.8.4, 9.8.3-P4
  • BIND 9 version 9.9.2, 9.9.1-P4
Share this