|
|
| |
|
| |
bind-dyndb-ldap: denial of service
| Package(s): | bind-dyndb-ldap |
CVE #(s): | CVE-2012-2134
|
| Created: | May 16, 2012 |
Updated: | May 23, 2012 |
| Description: |
From the Red Hat bugzilla:
A denial of service flaw was found in the way the bind-dyndb-ldap, a dynamic LDAP back-end plug-in for BIND providing LDAP database back-end capabilities, performed LDAP connection errors handling / attempted to recover, when an error during a LDAP search happened for a particular DNS query. When the Berkeley Internet Name Domain (BIND) server was patched to support dynamic loading of database back-ends, and the LDAP database back-end was enabled, a remote attacker could use this flaw to cause denial of service (named process hang) via DNS query for zone served by bind-dyndb-ldap. |
| Alerts: |
|
( Log in to post comments)
|
|
|