Junglewise Threat Intelligence

CVE-1999-0010: ISC BIND 8 denial of service via malformed DNS messages

CVE-1999-0010 · Severity: medium · CVSS 5 · Published 1998-04-08

Vendors: Isc.

Executive brief

BIND is a widely used system for translating human-readable website names into IP addresses. A vulnerability in BIND 8 allows an attacker to crash the service by sending specially crafted network messages. This can lead to a disruption of internet services and website accessibility for users relying on the affected server.

Technical details

A denial of service vulnerability exists in ISC BIND 8 releases due to improper handling of maliciously formatted DNS messages. A remote, unauthenticated attacker can trigger a service crash by sending specifically crafted DNS packets over the network. This flaw affects the core DNS processing logic, leading to a loss of availability for the name server. Patches were historically provided by various OS vendors including SGI, HP, and Sun Microsystems to address this issue in their respective distributions.

Affected products

  • ISC BIND 8 8.x

Timeline

  • 1998-04-08: disclosed
  • 1998-04-08: advisory

References