Input validation error in ISC BIND - CVE-2023-2829
Published: June 21, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A named instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (synth-from-dnssec) enabled can be remotely terminated using a zone with a malformed NSEC record.
Affected software
IBM Spectrum Conductor
IBM Spectrum Symphony
How to mitigate CVE-2023-2829
IBM Spectrum Conductor - update to 2.5.1 FP2
IBM Spectrum Symphony - update to 7.3.2 Fix 601711