CVE-2023-4408

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.10 % (43th)
0.10% Progress
Advisories 36
NVD Status Awaiting Analysis

The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected named instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers.
This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

CVE Status
PUBLISHED
NVD Status
Awaiting Analysis
CNA
Internet Systems Consortium (ISC)
Published Date
2024-02-13 14:15:45
(7 months ago)
Updated Date
2024-04-26 09:15:08
(4 months ago)
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...