AXFR/IXFR response processing flaw in BIND in ISC BIND - CVE-2016-6170
Published: July 8, 2016 / Updated: January 21, 2021
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to cause the target service to crash.
The vulnerability exists due to resource error in BIND. A remote primary DNS server can cause the target secondary DNS server to crash by sending a specially crafted AXFR response or IXFR response. A remote unauthenticated attacker may be able to send a specially crafted UPDATE message to cause the target server to crash.
Successful exploitation of this vulnerability may result in denial of service.
How to mitigate CVE-2016-6170
Cybersecurity Help is currently unaware of any official solution, which resolves this vulnerability.
A third-party unofficial patch is available at: https://github.com/sischkg/xfer-limit.