BIND DNS Servers Hit by 14 Security Flaws Enabling Cache Poisoning and Remote Crashes
Brief
Internet Systems Consortium has released security updates for BIND 9 after identifying 14 vulnerabilities that could allow attackers to poison DNS caches, crash exposed servers remotely , exhaust resources, or bypass DNSSEC protections.
Administrators running recursive BIND resolvers should apply the latest patched releases as soon as possible. The most serious issues affect the named daemon, which is widely used to provide authoritative and recursive DNS services across enterprise, ISP, and cloud environments.
Several of the flaws can be triggered by malicious DNS responses or specially crafted client queries, making internet-facing resolvers a key concern.
BIND DNS Servers Hit by Security Flaws
Two vulnerabilities directly address DNS cache-poisoning risks.
