BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of service (infinite loop) via a query for an RRSIG record whose answer is not in the cache, which causes BIND to repeatedly send RRSIG queries to the authoritative servers.
Weaknesses in this category are typically found in functionality that processes data. Data processing is the manipulation of input to retrieve or save information.
Link | Tags |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html | vendor advisory |
http://www.securityfocus.com/bid/41730 | vdb entry |
http://www.securitytracker.com/id?1024217 | vdb entry |
http://www.kb.cert.org/vuls/id/211905 | third party advisory us government resource |
http://secunia.com/advisories/40709 | third party advisory vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044445.html | vendor advisory |
http://secunia.com/advisories/40652 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2010/1884 | vdb entry vendor advisory |
http://www.isc.org/software/bind/advisories/cve-2010-0213 | vendor advisory |