Multiple products with DNS implementation contains a flaw that may allow a remote denial of service. By sending a DNS query that appears to originate from the localhost on port 53/udp, the system will respond to itself, hence entering an infinite loop which causes the system to consume all available CPU resources, resulting in a loss of availability.
Classification
Location:
Remote/Network Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Contact your vendor for an appropriate upgrade. An upgrade is required as there are no known workarounds.