#VU7091 Improper input validation in ISC BIND - CVE-2017-3140
Published: June 15, 2017 / Updated: June 15, 2017
ISC BIND
ISC
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when processing Response Policy Zones (RPZ) rules, when NSDNAME or NSIP policy rules are used. A remote attacker can trigger the affected server to enter an endless loop and repeatedly query a set of authoritative nameservers.
Successful exploitation of the vulnerability may allow an attacker to perform a denial of service attack.