CVE-2023-5680
MEDIUMDescription
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Is your site exposed to CVE-2023-5680?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| netapp | active_iq_unified_manager |
References
Frequently Asked Questions
What is CVE-2023-5680? +
How severe is CVE-2023-5680? +
What products are affected by CVE-2023-5680? +
How do I check if I'm vulnerable to CVE-2023-5680? +
Related Vulnerabilities
The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use …
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS …
The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause …
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is …
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when …
To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It …