PublicDateAtUSN: 2012-06-04 Candidate: CVE-2012-1667 PublicDate: 2012-06-05 16:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1667 http://www.isc.org/software/bind/advisories/cve-2012-1667 https://ubuntu.com/security/notices/USN-1462-1 Description: ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Dan Luther Assigned-to: mdeslaur CVSS: Patches_bind9: upstream_bind9: released (9.6-ESV-R7-P1, 9.7.6-P1, 9.8.3-P1) hardy_bind9: released (1:9.4.2.dfsg.P2-2ubuntu0.10) lucid_bind9: released (1:9.7.0.dfsg.P1-1ubuntu0.5) natty_bind9: released (1:9.7.3.dfsg-1ubuntu2.4) oneiric_bind9: released (1:9.7.3.dfsg-1ubuntu4.2) precise_bind9: released (1:9.8.1.dfsg.P1-4ubuntu0.1) devel_bind9: released (1:9.8.1.dfsg.P1-4ubuntu1)