FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

dns/bind9* -- servers using DNS64 can be crashed by a crafted query

Affected packages
bind99 < 9.9.2.1
bind99-base < 9.9.2.1
bind98 < 9.8.4.1
bind98-base < 9.8.4.1

Details

VuXML ID 2892a8e2-3d68-11e2-8e01-0800273fe665
Discovery 2012-11-27
Entry 2012-12-04

ISC reports:

BIND 9 nameservers using the DNS64 IPv6 transition mechanism are vulnerable to a software defect that allows a crafted query to crash the server with a REQUIRE assertion failure. Remote exploitation of this defect can be achieved without extensive effort, resulting in a denial-of-service (DoS) vector against affected servers.

References

CVE Name CVE-2012-5688