>> ISC BIND SIG and Excessive Recursive Queries Denial of Service Vulnerabilities
Title : ISC BIND SIG and Excessive Recursive Queries Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2006-3473 CVE ID : CVE-2006-4095 - CVE-2006-4096
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-09-06
Technical Description
Two vulnerabilities have been identified in ISC BIND, which could be exploited by attackers to cause a denial of service.
The first issue is due to an error when processing SIG queries, which could be exploited by attackers to crash recursive servers when more than one SIG(covered) Resource Record set (RRset) is returned or authoritative servers serving a RFC 2535 DNSSEC zone where there are multiple SIG(covered) RRsets.
The second flaw is due to an error when handling multiple recursive queries, which could be exploited by attackers to trigger a INSIST failure and cause certain responses to arrive after all the clients looking for the response have left the recursion queue.