A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the serve-stale feature and NSEC aggressive negative caching can in some cases cause undesirable behavior from named, such as a recursion loop or excessive logging. Deliberate exploitation of this condition could cause operational problems depending on the particular manifestation -- either degradation or denial of service. Affects BIND 9.12.0 and 9.12.1.
2019-01-16T20:29:00.877
2024-11-21T04:09:17.120
Modified
CVSSv3.0: 5.9 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | isc | bind | 9.12.0 | Yes |
Application | isc | bind | 9.12.1 | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | data_ontap_edge | - | Yes |