Description
When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
Product(s):
- ISC BIND 9.4.0
- ISC BIND 9.4.0 A1
- ISC BIND 9.4.0 A2
- ISC BIND 9.4.0 A3
- ISC BIND 9.4.0 A4
- ISC BIND 9.4.0 A5
- ISC BIND 9.4.0 A6
- ISC BIND 9.4.0 Alpha 1
- ISC BIND 9.4.0 Alpha 2
- ISC BIND 9.4.0 Alpha 3
- ISC BIND 9.4.0 Alpha 4
- ISC BIND 9.4.0 Alpha 5
- ISC BIND 9.4.0 Alpha 6
- ISC BIND 9.4.0 B1
- ISC BIND 9.4.0 B2
- ISC BIND 9.4.0 B3
- ISC BIND 9.4.0 B4
- ISC BIND 9.4.0 Beta 1
- ISC BIND 9.4.0 Beta 2
- ISC BIND 9.4.0 Beta 3
- ISC BIND 9.4.0 Beta 4
- ISC BIND 9.4.0 Release Candidate 1
- ISC BIND 9.4.0 Release Candidate 2
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-1999-0184, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-1999-0184 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.