BIND Dynamic Update DoS
CVE: CVE-2009-0696CERT: VU#725188Posting date: 2009-07-28Program Impacted: BINDVersions affected: BIND 9 (all versions)Severity: HighExploitable: remotelySummary: BIND denial of service (server crash) caused by receipt of a specific remote dynamic update message.
McAfee did a good job on summarizing how the attack works. You can follow it here if you are interested in the detail.
References:
POC exploit is available at:
Update: I found that there is a workaround that can be applied if case patch isn't available from vendor. Try this on your own risk.