[WID-SEC-2023-0207] Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 25.01.2023 Stand UPDATE 07.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung BIND (Berkeley Internet Name Domain) ist ein Open-Source-Softwarepaket, das einen Domain-Name-System-Server implementiert. Produkte UPDATE 26.02.2025 IBM SAN Volume Controller IBM Storwize IBM FlashSystem UPDATE 09.01.2025 Amazon Linux 2 UPDATE 11.04.2024 IBM QRadar SIEM 7.5 UPDATE 23.05.2023 Oracle Linux UPDATE 09.05.2023 Red Hat Enterprise Linux UPDATE 23.02.2023 NetApp ActiveIQ Unified Manager UPDATE 12.02.2023 SUSE Linux UPDATE 26.01.2023 Debian Linux 25.01.2023 Infoblox NIOS Internet Systems Consortium BIND <9.16.37 Internet Systems Consortium BIND <9.18.11 Internet Systems Consortium BIND <9.19.9 Internet Systems Consortium BIND <9.16.37-S1 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in Internet Systems Consortium BIND allow a remote, anonymous attacker to cause a Denial of Service, with a CVSS Base Score of 7.5 (High). Affected versions are BIND earlier than 9.16.37, 9.18.11, and 9.19.9, as well as the special release earlier than 9.16.37-S1. The advisory lists mitigations as available, but specific fixed versions or workarounds are not detailed in the provided text.