bind: Large RRSIG RRsets and Negative Caching can crash named
Published May 31, 2011
5.0
MEDIUMCVSS 2.0
EPSS 24.64%
Description
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
Affected products
No data.
- 9.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.1
- 9.0.1
- 9.0.1
- 9.1
- 9.1.0
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.2
- 9.1.2
- 9.1.3
- 9.1.3
- 9.1.3
- 9.1.3
- 9.2
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.1
- 9.2.1
- 9.2.1
- 9.2.2
- 9.2.2
- 9.2.2
- 9.2.2
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.5
- 9.2.5
- 9.2.5
- 9.2.6
- 9.2.6
- 9.2.7
- 9.2.7
- 9.2.7
- 9.2.7
- 9.2.8
- 9.2.9
- 9.2.9
- 9.3
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.1
- 9.3.1
- 9.3.1
- 9.3.2
- 9.3.2
- 9.3.3
- 9.3.3
- 9.3.3
- 9.3.3
- 9.3.4
- 9.3.5
- 9.3.5
- 9.3.5
- 9.3.5
- 9.3.6
- 9.3.6
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.1
- 9.4.2
- 9.4.2
- 9.4.2
- 9.4.2
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.5
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.2
- 9.5.2
- 9.5.2
- 9.5.2
- 9.5.2
- 9.5.2
- 9.5.2
- 9.5.3
- 9.5.3
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.1
- 9.6.1
- 9.6.1
- 9.6.1
- 9.6.1
- 9.6.1
- 9.6.2
- 9.6.2
- 9.6.2
- 9.6.2
- 9.6.2
- 9.6.2
- 9.6.3
- 9.6.3
- 9.6.3
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.1
- 9.7.1
- 9.7.1
- 9.7.1
- 9.7.1
- 9.7.2
- 9.7.2
- 9.7.2
- 9.7.2
- 9.7.2
- 9.7.3
- 9.7.3
- 9.8.0
- 9.8.0
- 9.8.0
- 9.8.0
No data.
Red Hat Enterprise Linux 5
bind97-32:9.7.0-6.P2.el5_6.2
Fixed · RHSA-2011:0845
Red Hat Enterprise Linux 6
bind-32:9.7.3-2.el6_1.P1.1
Fixed · RHSA-2011:0845
Red Hat Enterprise Linux 4
bind
Not affected
Red Hat Enterprise Linux 5
bind
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind97-32:9.7.0-6.P2.el5_6.2 | Fixed | RHSA-2011:0845 |
| Red Hat Enterprise Linux 6 | bind-32:9.7.3-2.el6_1.P1.1 | Fixed | RHSA-2011:0845 |
| Red Hat Enterprise Linux 4 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 5 | bind | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect bind packages shipped with Red Hat Enterprise Linux 4 and 5. It affected bind97 packages shipped with Red Hat Enterprise Linux 5 and bind packages shipped with Red Hat Enterprise Linux 6.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 24.64% (0.24638) | 97.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 24.64% (0.24638) | 97.60th | v5 (v2026.06.15) |
| Apr 16, 2026 | 11.87% (0.11874) | 93.75th | v4 (v2025.03.14) |
| Mar 3, 2026 | 20.86% (0.20860) | 95.54th | v4 (v2025.03.14) |
| Nov 30, 2025 | 34.01% (0.34010) | 96.78th | v4 (v2025.03.14) |
| Oct 19, 2025 | 46.23% (0.46235) | 97.48th | v4 (v2025.03.14) |
| May 17, 2025 | 34.01% (0.34010) | 96.72th | v4 (v2025.03.14) |
| Apr 21, 2025 | 51.93% (0.51929) | 97.72th | v4 (v2025.03.14) |
| Mar 30, 2025 | 57.95% (0.57948) | 97.99th | v4 (v2025.03.14) |
| Mar 29, 2025 | 65.12% (0.65116) | 97.88th | v4 (v2025.03.14) |
| Mar 17, 2025 | 57.95% (0.57948) | 97.96th | v4 (v2025.03.14) |
| Dec 12, 2024 | 94.31% (0.94308) | 99.30th | v3 (v2023.03.01) |
| Jun 19, 2023 | 94.31% (0.94308) | 98.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 94.70% (0.94703) | 98.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 17.84% (0.17838) | 96.26th | v2 (v2022.01.01) |
| Apr 1, 2022 | 17.84% (0.17838) | 95.93th | v2 (v2022.01.01) |
| Feb 4, 2022 | 17.84% (0.17838) | 93.36th | v2 (v2022.01.01) |
References (29)
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061082.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061401.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061405.html vendor-advisoryx_refsource_FEDORA
- http://marc.info/?l=bugtraq&m=142180687100892&w=2 vendor-advisoryx_refsource_HP
- http://osvdb.org/72540 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/44677 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44719 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/44741 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44744 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44758 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44762 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44783 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44929 third-party-advisoryx_refsource_SECUNIA
- http://security.freebsd.org/advisories/FreeBSD-SA-11:02.bind.asc vendor-advisoryx_refsource_FREEBSD
- http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.685026 vendor-advisoryx_refsource_SLACKWARE
- http://support.apple.com/kb/HT5002 x_refsource_CONFIRM
- http://www.debian.org/security/2011/dsa-2244 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/795694 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:104 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2011-0845.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/48007 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1025572 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2011-1910 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=708301 x_refsource_CONFIRMIssue Tracking
- https://hermes.opensuse.org/messages/8699912 vendor-advisoryx_refsource_SUSE
- https://nvd.nist.gov/vuln/detail/CVE-2011-1910
- https://www.cve.org/CVERecord?id=CVE-2011-1910
- https://www.isc.org/software/bind/advisories/cve-2011-1910 x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.