CVE-1999-0849
CVSS 2.0 Score 5 of 10 (medium)
Details
Summary
CVE-1999-0849 is a denial-of-service vulnerability affecting the BIND named software. The issue arises due to a lack of proper validation of maximum label count in DNS queries, allowing an attacker to send specially crafted packets that cause the named process to crash or consume excessive resources, resulting in a denial-of-service condition. This vulnerability can be exploited by sending malformed queries with an excessive number of labels, leading to service disruption. It is recommended that administrators update their BIND software to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ISC BIND
Affected Vendors
- Internet Storm Center