CVE-1999-0849

CVSS 2.0 Score 5 of 10 (medium)

Details

Published Nov 10, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-0849 is a denial-of-service vulnerability affecting the BIND named software. The issue arises due to a lack of proper validation of maximum label count in DNS queries, allowing an attacker to send specially crafted packets that cause the named process to crash or consume excessive resources, resulting in a denial-of-service condition. This vulnerability can be exploited by sending malformed queries with an excessive number of labels, leading to service disruption. It is recommended that administrators update their BIND software to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • ISC BIND

Affected Vendors

  • Internet Storm Center