Short Name |
DNS:DYNAMICUPDATE |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
DNS |
Keywords |
BIND Dynamic Update Denial of Service |
Release Date |
2009/07/30 |
Update Number |
1473 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against DNS BIND. A successful attack can result in a denial-of-service condition.
ISC BIND is prone to a remote denial-of-service vulnerability because the software fails to properly handle specially crafted dynamic update requests. Successfully exploiting this issue allows remote attackers to crash affected DNS servers, denying further service to legitimate users. Other attacks are also possible. Versions prior to BIND 9.4.3-P3, 9.5.1-P3, and 9.6.1-P3 are vulnerable.