<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:41:41 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-05771</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05771</link>
      <description>bdu:2024-05771</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05771</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-0760</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-0760</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:stream: bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:stream: bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-0760</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0618 — De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0618</link>
      <description>certfr-2024-avi-0618</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0618</guid>
    </item>
    <item>
      <title>EUVD-2026-217108</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217108</link>
      <description>EUVD-2026-217108</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217108</guid>
    </item>
    <item>
      <title>fkie_cve-2024-0760</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-0760</link>
      <description>&lt;p&gt;A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. 
This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. 
This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-0760</guid>
    </item>
    <item>
      <title>GHSA-v3r3-642v-rqj8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v3r3-642v-rqj8</link>
      <description>&lt;p&gt;A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. 
This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. 
This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v3r3-642v-rqj8</guid>
    </item>
    <item>
      <title>gsd-2024-0760</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-0760</link>
      <description>gsd-2024-0760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-0760</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-0760 — A flood of DNS messages over TCP may make the server unstable</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-0760</link>
      <description>msrc_CVE-2024-0760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-0760</guid>
    </item>
    <item>
      <title>OESA-2024-2014 — bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2014</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: bind&lt;/p&gt;
&lt;p&gt;Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;amp;quot;NSEC3&amp;amp;quot; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.(CVE-2023-50868)&#13;
&#13;
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. 
This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.(CVE-2024-0760)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: bind&lt;/p&gt;
&lt;p&gt;Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;amp;quot;NSEC3&amp;amp;quot; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.(CVE-2023-50868)&#13;
&#13;
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. 
This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.(CVE-2024-0760)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2014</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14217-1 — bind-9.20.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14217-1</link>
      <description>&lt;p&gt;bind-9.20.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind-9.20.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14217-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2636-1 — Security update for bind</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2636-1</link>
      <description>&lt;p&gt;Security update for bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2636-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-0760</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-0760</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp, Ubuntu:25.10: isc-dhcp, Ubuntu:26.04:LTS: isc-dhcp&lt;/p&gt;
&lt;p&gt;A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp, Ubuntu:25.10: isc-dhcp, Ubuntu:26.04:LTS: isc-dhcp&lt;/p&gt;
&lt;p&gt;A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-0760</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1700 — Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1700</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1700</guid>
    </item>
  </channel>
</rss>
