CVE-2023-5680
MEDIUMDescription
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Is your site exposed to CVE-2023-5680?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| isc | bind |
| netapp | active_iq_unified_manager |
References
Frequently Asked Questions
What is CVE-2023-5680? +
How severe is CVE-2023-5680? +
What products are affected by CVE-2023-5680? +
How do I check if I'm vulnerable to CVE-2023-5680? +
Related Vulnerabilities
The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use …
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving …
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) …
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to …
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote …
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS …