|
ISC BIND named contains a flaw related to the allowing of queries. If the 'allow-query' ACL is not set properly in the zone statement, it does not check the 'view' or 'global' options before defaulting to allowing queries. This issue may allow a remote attacker to bypass query restrictions.
|