Vulnerability Bulletins |
DSA-3420 bind9 - security update |
|
| Affected software | Debian |
|
It was discovered that the BIND DNS server does not properly handle theparsing of incoming responses, allowing some records with an incorrectclass to be accepted by BIND instead of being rejected as malformed.This can trigger a REQUIRE assertion failure when those records aresubsequently cached. A remote attacker can exploit this flaw to cause adenial of service against servers performing recursive queries. More info: https://www.debian.org/security/2015/dsa-3420 |
|






