BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bind | Isc | 9.2.0 (including) | 9.2.0 (including) |
| Bind | Isc | 9.2.1 (including) | 9.2.1 (including) |
| Bind | Isc | 9.2.2 (including) | 9.2.2 (including) |
| Bind | Isc | 9.2.3 (including) | 9.2.3 (including) |
| Bind | Isc | 9.2.4 (including) | 9.2.4 (including) |
| Bind | Isc | 9.2.5 (including) | 9.2.5 (including) |
| Bind | Isc | 9.2.6 (including) | 9.2.6 (including) |
| Bind | Isc | 9.3 (including) | 9.3 (including) |
| Bind | Isc | 9.3.0 (including) | 9.3.0 (including) |
| Bind | Isc | 9.3.1 (including) | 9.3.1 (including) |
| Bind | Isc | 9.3.2 (including) | 9.3.2 (including) |
| Red Hat Desktop version 3 | RedHat | * | |
| Red Hat Enterprise Linux AS version 3 | RedHat | * | |
| Red Hat Enterprise Linux AS version 4 | RedHat | * | |
| Red Hat Enterprise Linux Desktop version 4 | RedHat | * | |
| Red Hat Enterprise Linux ES version 3 | RedHat | * | |
| Red Hat Enterprise Linux ES version 4 | RedHat | * | |
| Red Hat Enterprise Linux WS version 3 | RedHat | * | |
| Red Hat Enterprise Linux WS version 4 | RedHat | * | |
| Bind9 | Ubuntu | dapper | * |
| Bind9 | Ubuntu | devel | * |
| Bind9 | Ubuntu | edgy | * |
| Bind9 | Ubuntu | feisty | * |