UBUNTU-CVE-2023-4408
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-4408
UBUNTU-CVE-2023-4408
Summary:
Details: The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
References: https://ubuntu.com/security/CVE-2023-4408, https://kb.isc.org/docs/cve-2023-4408, https://ubuntu.com/security/notices/USN-6633-1, https://ubuntu.com/security/notices/USN-6642-1, https://www.cve.org/CVERecord?id=CVE-2023-4408
Affected packages
Package
Name: bind9
Purl: pkg:deb/ubuntu/bind9?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
