Lucene search

K
cve[email protected]CVE-2010-3613
HistoryDec 06, 2010 - 1:44 p.m.

CVE-2010-3613

2010-12-0613:44:54
CWE-264
web.nvd.nist.gov
46
In Wild
isc bind
denial of service
vulnerability
nvd
cve-2010-3613

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

8.2 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.4%

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.

Affected configurations

NVD
Node
iscbindMatch9.6esv
OR
iscbindMatch9.6r1esv
OR
iscbindMatch9.6r2esv
OR
iscbindMatch9.6.2
OR
iscbindMatch9.6.2b1
OR
iscbindMatch9.6.2p1
OR
iscbindMatch9.6.2p2
OR
iscbindMatch9.7.0
OR
iscbindMatch9.7.0a1
OR
iscbindMatch9.7.0a2
OR
iscbindMatch9.7.0a3
OR
iscbindMatch9.7.0b1
OR
iscbindMatch9.7.0b2
OR
iscbindMatch9.7.0b3
OR
iscbindMatch9.7.0p1
OR
iscbindMatch9.7.0p2
OR
iscbindMatch9.7.0rc1
OR
iscbindMatch9.7.0rc2
OR
iscbindMatch9.7.1
OR
iscbindMatch9.7.1b1
OR
iscbindMatch9.7.1p1
OR
iscbindMatch9.7.1p2
OR
iscbindMatch9.7.1rc1
OR
iscbindMatch9.7.2
OR
iscbindMatch9.7.2p1
OR
iscbindMatch9.7.2p2

References

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

8.2 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.4%