Summary
The remote host is missing an update to bind9
announced via advisory DSA 2547-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202547-1
Insight
It was discovered that BIND, a DNS server, does not handle DNS records properly which approach size limits inherent to the DNS protocol. An attacker could use crafted DNS records to crash the BIND server process, leading to a denial of service.
For the stable distribution (squeeze), this problem has been fixed in version 1:9.7.3.dfsg-1~squeeze7.
We recommend that you upgrade your bind9 packages.
Severity
Classification
-
CVE CVE-2012-4244 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities