Summary
The remote host is missing an update to the system as announced in the referenced advisory FreeBSD-SA-09:12.bind.asc
Solution
Upgrade your system to the appropriate stable release or security branch dated after the correction date
https://secure1.securityspace.com/smysecure/catid.html?in=FreeBSD-SA-09:12.bind.asc
Insight
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Internet Domain Name Server.
Dynamic update messages may be used to update records in a master zone on a nameserver.
When named(8) receives a specially crafted dynamic update message an internal assertion check is triggered which causes named(8) to exit.
To trigger the problem, the dynamic update message must contains a record of type ANY and at least one resource record set (RRset) for this fully qualified domain name (FQDN) must exist on the server.
Severity
Classification
-
CVE CVE-2009-0696 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
Related Vulnerabilities