Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34560.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-34560
Upstream
Published
2024-02-13T14:15:45Z
Modified
2026-04-01T05:11:32.075429Z
Summary
CVE-2023-4408 affecting package bind for versions less than 9.19.21-1
Details

The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected named instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

References

Affected packages

Azure Linux:3 / bind

Package

Name
bind
Purl
pkg:rpm/azure-linux/bind

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.19.21-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34560.json"