Vulnerability Report

CVE-2011-1910

Title: Isc Bind Denial of Service (DoS)

DoS

Proof Of Concept

No public PoC currently indexed for CVE-2011-1910.

CWE Category CWE-189
Published Date May 31, 2011
Modified Date Jun 16, 2026
Exploit Status Not Found
Score 5.0 CVSS v2.0
Exploit Probability (EPSS)
24.64%

Vulnerability Summary

CVE-2011-1910: Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.

Impacted Vendors

Reference Links

http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061082.html http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061401.html http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061405.html http://marc.info/?l=bugtraq&m=142180687100892&w=2 http://osvdb.org/72540 http://secunia.com/advisories/44677 http://secunia.com/advisories/44719 http://secunia.com/advisories/44741 http://secunia.com/advisories/44744 http://secunia.com/advisories/44758 http://secunia.com/advisories/44762 http://secunia.com/advisories/44783 http://secunia.com/advisories/44929 http://security.freebsd.org/advisories/FreeBSD-SA-11:02.bind.asc http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.685026 http://support.apple.com/kb/HT5002 http://www.debian.org/security/2011/dsa-2244 http://www.kb.cert.org/vuls/id/795694 http://www.mandriva.com/security/advisories?name=MDVSA-2011:104 http://www.redhat.com/support/errata/RHSA-2011-0845.html http://www.securityfocus.com/bid/48007 http://www.securitytracker.com/id?1025572 https://bugzilla.redhat.com/show_bug.cgi?id=708301 https://hermes.opensuse.org/messages/8699912 https://www.isc.org/software/bind/advisories/cve-2011-1910 http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061082.html http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061401.html http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061405.html http://marc.info/?l=bugtraq&m=142180687100892&w=2 http://osvdb.org/72540 http://secunia.com/advisories/44677 http://secunia.com/advisories/44719 http://secunia.com/advisories/44741 http://secunia.com/advisories/44744 http://secunia.com/advisories/44758 http://secunia.com/advisories/44762 http://secunia.com/advisories/44783 http://secunia.com/advisories/44929 http://security.freebsd.org/advisories/FreeBSD-SA-11:02.bind.asc http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.685026 http://support.apple.com/kb/HT5002 http://www.debian.org/security/2011/dsa-2244 http://www.kb.cert.org/vuls/id/795694 http://www.mandriva.com/security/advisories?name=MDVSA-2011:104 http://www.redhat.com/support/errata/RHSA-2011-0845.html http://www.securityfocus.com/bid/48007 http://www.securitytracker.com/id?1025572 https://bugzilla.redhat.com/show_bug.cgi?id=708301 https://hermes.opensuse.org/messages/8699912 https://www.isc.org/software/bind/advisories/cve-2011-1910
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:N/I:N/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2011-1910 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected Stack

No specific products linked.