BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
Summary
The Internet Systems Consortium (ISC) has released updates for BIND 9, addressing fourteen security flaws. One critical vulnerability allows an unauthenticated sender to crash the BIND server process via a single request when using DNS-over-HTTPS (DoH).
IFF Assessment
This article reports on multiple security vulnerabilities in BIND 9, a widely used DNS server, which can be exploited by attackers to cause denial-of-service or potentially other impacts.
Severity
The vulnerability allows for an unauthenticated crash of the BIND server process via DNS-over-HTTPS, indicating a high severity due to the potential for denial-of-service and the lack of authentication required.
Defender Context
This update is critical for organizations running BIND 9 DNS servers, especially those using DNS-over-HTTPS. Defenders should prioritize patching to mitigate the risk of unauthenticated denial-of-service attacks. This highlights the importance of keeping critical infrastructure software like DNS servers up-to-date.