Resource exhaustion in ISC BIND - CVE-2023-4236
Published: September 20, 2023
Vulnerability identifier: #VU80930
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4236
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling DNS-over-TLS queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
ISC BIND
Debian Linux
Ubuntu
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
Redis for Pivotal Platform
VMware Tanzu Operations Manager
bind9 (Ubuntu package)
bind9 (Debian package)
bind
bind-dyndb-ldap
Debian Linux
Ubuntu
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
Redis for Pivotal Platform
VMware Tanzu Operations Manager
bind9 (Ubuntu package)
bind9 (Debian package)
bind
bind-dyndb-ldap
How to mitigate CVE-2023-4236
Install updates from vendor's website.
ISC BIND - addressed in versions 9.18.19, 9.18.19-S1
VMware Tanzu Operations Manager - update to 3.0.17
bind9 (Ubuntu package) - addressed in versions 1:9.16.1-0ubuntu2.16, 1:9.18.12-0ubuntu0.22.04.3, 1:9.18.12-1ubuntu1.2
bind9 (Debian package) - addressed in versions 1:9.16.44-1~deb11u1, 1:9.18.19-1~deb12u1
bind - addressed in versions 9.18.19-1.fc37, 9.18.19-1.fc38, 9.18.19-1.fc39, 9.18.19-1.fc40
bind-dyndb-ldap - addressed in versions 11.10-17.fc37, 11.10-21.fc38, 11.10-21.fc39, 11.10-21.fc40
VMware Tanzu Operations Manager - update to 3.0.17
bind9 (Ubuntu package) - addressed in versions 1:9.16.1-0ubuntu2.16, 1:9.18.12-0ubuntu0.22.04.3, 1:9.18.12-1ubuntu1.2
bind9 (Debian package) - addressed in versions 1:9.16.44-1~deb11u1, 1:9.18.19-1~deb12u1
bind - addressed in versions 9.18.19-1.fc37, 9.18.19-1.fc38, 9.18.19-1.fc39, 9.18.19-1.fc40
bind-dyndb-ldap - addressed in versions 11.10-17.fc37, 11.10-21.fc38, 11.10-21.fc39, 11.10-21.fc40
External References
Related Security Bulletins
- Multiple denial of service vulnerabilities in ISC BIND
- Ubuntu update for bind9
- Debian update for bind9
- Fedora 38 update for bind, bind-dyndb-ldap
- Fedora 37 update for bind, bind-dyndb-ldap
- Fedora 40 update for bind, bind-dyndb-ldap
- Fedora 39 update for bind, bind-dyndb-ldap
- VMware Tanzu products update for Bind