Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4022

Опубликовано: 25 нояб. 2009
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 2.6

Описание

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

1:9.3.2-2ubuntu1.9
devel

not-affected

1:9.6.1.dfsg.P2-1~1build1
hardy

released

1:9.4.2.dfsg.P2-2ubuntu0.4
intrepid

released

1:9.5.0.dfsg.P2-1ubuntu3.4
jaunty

released

1:9.5.1.dfsg.P2-1ubuntu0.3
karmic

released

1:9.6.1.dfsg.P1-3ubuntu0.2
upstream

released

1:9.6.1.dfsg.P2-1

Показывать по

EPSS

Процентиль: 95%
0.20044
Средний

2.6 Low

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

nvd
почти 16 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

debian
почти 16 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before ...

github
больше 3 лет назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

oracle-oval
почти 16 лет назад

ELSA-2009-1620: bind security update (MODERATE)

EPSS

Процентиль: 95%
0.20044
Средний

2.6 Low

CVSS2