Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3613

Опубликовано: 01 дек. 2010
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bind97Affected
Red Hat Enterprise Linux 4bindFixedRHSA-2010:100020.12.2010
Red Hat Enterprise Linux 5bindFixedRHSA-2010:097613.12.2010
Red Hat Enterprise Linux 6bindFixedRHSA-2010:097513.12.2010

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=658974bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named

EPSS

Процентиль: 82%
0.01902
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.

nvd
больше 14 лет назад

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.

debian
больше 14 лет назад

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, an ...

github
около 3 лет назад

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.

oracle-oval
больше 14 лет назад

ELSA-2010-0975: bind security update (IMPORTANT)

EPSS

Процентиль: 82%
0.01902
Низкий

4 Medium

CVSS2