Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-3615

Опубликовано: 06 дек. 2010
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.

Комментарий

Per: http://www.isc.org/software/bind/advisories/cve-2010-3615

'This bug doesn't affect allow-recursion or allow-query-cache acls, since they are not relevant to a zone for which the server is authoritative. '

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:isc:bind:9.7.2:p2:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.0529
Низкий

5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 15 лет назад

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.

redhat
около 15 лет назад

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.

debian
около 15 лет назад

named in ISC BIND 9.7.2-P2 does not check all intended locations for a ...

github
больше 3 лет назад

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.

EPSS

Процентиль: 90%
0.0529
Низкий

5 Medium

CVSS2

Дефекты

CWE-264