Re: Questions about CVE-2024-11187

2025-03-04 Thread Laszlo Szollosi
03. 25 9:53, Laszlo Szollosi wrote: > > Many thanks for your response. > > By mitigation, I mean we have seen an increase in resource utilization, > > but it would have been much worse without the 'minimal-responses' > > setting (reduced impact). > > By preventi

Re: Questions about CVE-2024-11187

2025-03-04 Thread Laszlo Szollosi
auth-nxdomain yes; notifyno; transfers-per-ns 16; empty-zones-enableyes; }; // // BIND 9 statistics fragment // statistics-channels { inet 127.0.0.1 port 8080 allow { localhost; }; inet ::1 port 8080 allow { localhost; }; }; On Mon, 3 Mar 2025

Questions about CVE-2024-11187

2025-02-28 Thread Laszlo Szollosi
Hi Everyone, I'm hoping I can get some insight about the vulnerability mentioned above. We had been running BIND 9.20.4 in our infrastructure, and upgraded to 9.20.6 just recently. CVE-2024-12705 does not apply to our setup, yet we have a suspicion that we were impacted by CVE-2024-11187, but cann