Bind9 Dynamic Update DoS Exploit

lunchb0xlunchb0x Lansing, MI New
edited July 2009 in Science & Tech
https://www.isc.org/node/474

All you have to do is point a specially crafted perl script a domain that bind is a master is master for (most installs of bind are masters of localhost) and bam, bind crashes. The fix is in source now, but hasn't hit the CentOS repos atleast. If you're running a DNS server running bind9, you should probably upgrade.

Comments

  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited July 2009
    Thanks for the heads up!
Sign In or Register to comment.