CVE-2024-0760

Name
CVE-2024-0760
Description
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://kb.isc.org/docs/cve-2024-0760
http://www.openwall.com/lists/oss-security/2024/07/23/1
http://www.openwall.com/lists/oss-security/2024/07/31/2

Match rules

CPE URI Source package Min version Max version
bind-9 >= 9.18.1 <= 9.18.27
bind-9 >= 9.19.0 <= 9.19.24
bind-9 >= 9.18.11-S1 <= 9.18.27-S1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
bind edge-main 9.18.28-r0 None fixed
bind edge-main 9.18.27-r1 Mike Crute <mike@crute.us> possibly vulnerable
bind 3.22-main 9.18.28-r0 None fixed
bind 3.21-main 9.18.28-r0 None fixed
bind 3.20-main 9.18.31-r0 Mike Crute <mike@crute.us> fixed
bind 3.20-main 9.18.27-r0 Mike Crute <mike@crute.us> possibly vulnerable
bind 3.19-main 9.18.31-r0 Mike Crute <mike@crute.us> fixed
bind 3.19-main 9.18.24-r1 Mike Crute <mike@crute.us> possibly vulnerable
bind 3.18-main 9.18.31-r0 Mike Crute <mike@crute.us> fixed
bind 3.18-main 9.18.24-r0 Mike Crute <mike@crute.us> possibly vulnerable
bind 3.17-main 9.18.31-r0 None fixed
bind 3.17-main 9.18.24-r0 None possibly vulnerable