CVE-2024-4076

high

Description

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.

References

https://securityaffairs.com/166190/security/bind-updates-high-severity-dos-bugs.html

https://kb.isc.org/docs/cve-2024-4076

http://www.openwall.com/lists/oss-security/2024/07/31/2

http://www.openwall.com/lists/oss-security/2024/07/23/1

Details

Source: Mitre, NVD

Published: 2024-07-23

Updated: 2024-08-01

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High