CVE-2012-3817
ISC BIND 9.4.x-9.7.6-P1, 9.8.x-9.8.3-P1, 9.9.x-9.9.1-P1, 9.6-ESV-R7-P1 - Denial of Service via DNSSEC Validation Cache
Title source: llmDescription
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
References (12)
Core 12
Core References
Vendor Advisory vendor-advisory
x_refsource_slackware
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/51096
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1123.html
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-08/msg00015.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1122.html
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1027296
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2012/dsa-2517
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-08/msg00013.html
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1518-1
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5880
Vendor Advisory x_refsource_confirm
https://kb.isc.org/article/AA-00729
Scores
EPSS
0.0669
EPSS Percentile
91.4%
Details
CWE
CWE-20
Status
published
Products (19)
isc/bind
9.4
isc/bind
9.4.0 (2 CPE variants)
isc/bind
9.4.1
isc/bind
9.4.2
isc/bind
9.4.3 (2 CPE variants)
isc/bind
9.5
isc/bind
9.5.0 (2 CPE variants)
isc/bind
9.5.1 (3 CPE variants)
isc/bind
9.5.2 (2 CPE variants)
isc/bind
9.5.3 (2 CPE variants)
... and 9 more
Published
Jul 25, 2012
Tracked Since
Feb 18, 2026