CVE-2012-3817

Priority
Medium
Description
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before
9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when
DNSSEC validation is enabled, does not properly initialize the
failing-query cache, which allows remote attackers to cause a denial of
service (assertion failure and daemon exit) by sending many queries.
References
Assigned-to
mdeslaur
Package
Source: bind9 (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):not-affected (code not present)
Ubuntu 10.04 LTS (Lucid Lynx):released (1:9.7.0.dfsg.P1-1ubuntu0.6)
Ubuntu 11.04 (Natty Narwhal):released (1:9.7.3.dfsg-1ubuntu2.5)
Ubuntu 11.10 (Oneiric Ocelot):released (1:9.7.3.dfsg-1ubuntu4.3)
Ubuntu 12.04 LTS (Precise Pangolin):released (1:9.8.1.dfsg.P1-4ubuntu0.2)
Ubuntu 12.10 (Quantal Quetzal):released (1:9.8.1.dfsg.P1-4ubuntu2)
More Information

Valid XHTML 1.0 Strict

Updated: 2012-07-27 12:14:29 UTC (commit 5564)