BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Summary

The Internet Systems Consortium (ISC) has released updates for BIND 9, addressing fourteen security flaws. One critical vulnerability allows an unauthenticated sender to crash the BIND server process via a single request when using DNS-over-HTTPS (DoH).

IFF Assessment

FOE

This article reports on multiple security vulnerabilities in BIND 9, a widely used DNS server, which can be exploited by attackers to cause denial-of-service or potentially other impacts.

Severity

9.0 Critical (AI Estimated)

The vulnerability allows for an unauthenticated crash of the BIND server process via DNS-over-HTTPS, indicating a high severity due to the potential for denial-of-service and the lack of authentication required.

Defender Context

This update is critical for organizations running BIND 9 DNS servers, especially those using DNS-over-HTTPS. Defenders should prioritize patching to mitigate the risk of unauthenticated denial-of-service attacks. This highlights the importance of keeping critical infrastructure software like DNS servers up-to-date.

Read Full Story →