Short Name |
DNS:EXPLOIT:BIND-MULT-RRSET |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
DNS |
Keywords |
ISC BIND DNSSEC Validation Multiple RRsets Denial of Service |
Release Date |
2010/09/30 |
Update Number |
1783 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against ISC BIND. A successful attack can lead to a denial-of-service condition.
ISC BIND is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed DNSSEC validation requests. Successfully exploiting this issue allows remote attackers to crash affected DNS servers, denying further service to legitimate users.