#VU48663 NULL pointer dereference in ISC BIND
Published: November 26, 2020
ISC BIND
ISC
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. After a Negative Trust Anchor (NTA) is added, BIND performs periodic checks to see if it is still necessary. If BIND encountered a failure while creating a query to perform such a check, it attempted to dereference a NULL pointer, resulting in a crash. A remote user can pass specially crafted data to the application and perform a denial of service (DoS) attack.