Candidate: CVE-2010-0213 PublicDate: 2010-07-28 12:48:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0213 Description: BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of service (infinite loop) via a query for an RRSIG record whose answer is not in the cache, which causes BIND to repeatedly send RRSIG queries to the authoritative servers. Ubuntu-Description: Notes: sbeattie> only affects 9.7.1 and 9.7.1-P1, earlier versions okay. Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_bind9: upstream_bind9: released (9.7.1-P2) dapper_bind9: not-affected (1:9.3.2-2ubuntu1.11) hardy_bind9: not-affected (1:9.4.2.dfsg.P2-2ubuntu0.5) jaunty_bind9: not-affected (1:9.5.1.dfsg.P2-1ubuntu0.4) karmic_bind9: not-affected (1:9.6.1.dfsg.P1-3ubuntu0.3) lucid_bind9: not-affected (1:9.7.0.dfsg.P1-1) devel_bind9: released (1:9.7.1.dfsg.P2-2~build1)