CVE-2023-5680

MEDIUM

BIND <9.11.37-S1-9.18.21-S1 - Info Disclosure

Title source: llm
STIX 2.1

Description

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://kb.isc.org/docs/cve-2023-5680

Scores

CVSS v3 5.3
EPSS 0.0010
EPSS Percentile 28.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (25)
isc/bind 9.11.3 s1 (2 CPE variants)
isc/bind 9.11.4 s1
isc/bind 9.11.5 s3 (3 CPE variants)
isc/bind 9.11.6 s1
isc/bind 9.11.7 s1
isc/bind 9.11.8 s1
isc/bind 9.11.12 s1
isc/bind 9.11.21 s1
isc/bind 9.11.27 s1
isc/bind 9.11.29 s1
... and 15 more
Published Feb 13, 2024
Tracked Since Feb 18, 2026