Junglewise Threat Intelligence

CVE-1999-0011: ISC BIND Denial of Service via CNAME and zone transfer

CVE-1999-0011 · Severity: medium · CVSS 5.4 · Published 1998-04-08

Technologies: Isc Bind. Vendors: Isc.

Executive brief

A vulnerability in the BIND domain name service software can allow an attacker to disrupt internet name resolution services. By sending specially crafted requests related to CNAME records or zone transfers, an attacker can cause the service to become unresponsive. This could prevent users from accessing websites or internal network resources that rely on the affected DNS server.

Technical details

BIND 4.9 and BIND 8 releases are susceptible to denial of service (DoS) attacks. The vulnerability is triggered through malformed or specific CNAME records and during zone transfer operations. An attacker can exploit this by sending malicious DNS queries or participating in zone transfers to crash the BIND daemon or cause it to hang. This results in a loss of DNS resolution capabilities for the network segment served by the affected host. Patches were historically released by various OS vendors including Sun, HP, and SGI to address these issues in their respective BIND distributions.

Affected products

  • ISC BIND 4.9, 8.x

Timeline

  • 1998-04-08: disclosed
  • 1998-04-08: advisory

References

Related threats