CVE-2024-11187

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
Configurations

No configuration.

History

11 Feb 2025, 19:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/02/msg00011.html -

07 Feb 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) Es posible construir una zona de manera que algunas consultas generen respuestas que contengan numerosos registros en la sección Adicional. Un atacante que envíe muchas consultas de este tipo puede provocar que el servidor autorizado o un solucionador independiente utilicen recursos desproporcionados para procesar las consultas. Por lo general, será necesario que las zonas hayan sido deliberadamente manipulado para atacar esta exposición. Este problema afecta a las versiones de BIND 9 9.11.0 a 9.11.37, 9.16.0 a 9.16.50, 9.18.0 a 9.18.32, 9.20.0 a 9.20.4, 9.21.0 a 9.21.3, 9.11.3-S1 a 9.11.37-S1, 9.16.8-S1 a 9.16.50-S1 y 9.18.11-S1 a 9.18.32-S1.
References
  • () https://security.netapp.com/advisory/ntap-20250207-0002/ -

29 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 22:15

Updated : 2025-02-11 19:15


NVD link : CVE-2024-11187

Mitre link : CVE-2024-11187

CVE.ORG link : CVE-2024-11187


JSON object : View

Products Affected

No product.

CWE
CWE-405

Asymmetric Resource Consumption (Amplification)