CVE-2017-3135: denial-of-service vulnerability in ISC BIND 9
ISC announced CVE-2017-3135, a denial-of-service vulnerability that can affect resolvers using both DNS64 and RPZ to rewrite responses for the same view.
This affects all BIND 9.9 releases since 9.9.3, all BIND 9.10 releases, and all BIND 9.11 releases, including the 9.9.10b1, 9.10.5b1, and 9.11.1b1 releases.
Mitigation: Upgrade to the patched release most closely related to your current version of BIND. These can all be downloaded from http://www.isc.org/downloads.
- BIND 9 version 9.9.9-P6
- BIND 9 version 9.10.4-P6
- BIND 9 version 9.11.0-P3
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
- BIND 9 version 9.9.9-S8
Press release April 2023: Situational Security Alerts from CIRT
21 Apr 2023 - Articles, English articles, News, Notice, Security Advisories & Alerts
Security Best Practices
29 Mar 2023 - Security Advisories & Alerts