The Network Systems Association fixes three vulnerabilities in DNS suite BIND 9 to prevent hackers from attacking DoS.
CTOnews.com, July 1, Bind is an open source software that implements DNS servers. At present, more than half of the DNS servers in the market are built with Bind, so it has become the de facto industry standard in DNS.
The ▲ BIND9 icon, the source iscBIND9 version, was first released in September 2000 and has made a major rewrite of almost all aspects of the underlying BIND architecture. The Network Systems Association (ISC) recently released DNS software BIND 9 updated versions 9.16.42,9.18.16,9.19.14, 9.16.42-S1 and 9.18.16-S1, mainly fixing three of these vulnerabilities to prevent hackers from exploiting these vulnerabilities to carry out denial of service attacks (DoS).
According to CTOnews.com, the list of fixed vulnerabilities is as follows:
CVE-2023-2828
CVE-2023-2829
CVE-2023-2911.
▲ diagram source CVSS
It is reported that the CVSS risk score of these vulnerabilities is 7.5. through such vulnerabilities, hackers can carry out DoS attacks on DNS devices, which can lead to memory exhaustion of the attacked DNS devices or downtime of the BIND server. Given the base number of BIND 9 deployed on DNS devices around the world, it is necessary to fix such vulnerabilities.