RULE(RULE ID:105019)

Rule General Information
Release Date: 2016-07-25
Rule Name: PROTOCOL-DNS ISC BIND RRSIG Rrsets Denial of Service Vulnerability -1 (CVE-2011-1910)
Severity:
CVE ID:
Rule Protection Details
Description: Off-by-one error in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:48007
SecurityTrackerID:1025572
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://www.isc.org/software/bind/advisories/cve-2011-1910