CVE-2011-0414 describes a denial-of-service vulnerability affecting ISC BIND versions 9.7.1 through 9.7.2-P3 when configured as an authoritative server. Remote attackers can trigger a deadlock and daemon hang by sending a query during an IXFR transfer or DDNS update. This vulnerability has a CVSS score of 7.1, indicating a high severity with network-based attacks and medium complexity leading to a complete loss of availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is listed, the CVE has received some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.7.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.7.1:*:*:*:*:*:*:* | ||
9.7.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.7.1:p1:*:*:*:*:*:* | ||
9.7.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.7.1:p2:*:*:*:*:*:* | ||
9.7.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.7.1:rc1:*:*:*:*:*:* | ||
9.7.2CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.7.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.