Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10756
HistoryJan 15, 2019 - 8:51 a.m.

Insecure Caching

2019-01-1508:51:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.01 Low

EPSS

Percentile

83.7%

bind is vulnerable to ghost domain names attack. This is due to a flaw in the way BIND handles the updates of cached name server (NS) resource records. A malicious owner of a DNS domain is able to abuse the vulnerability to keep the domain resolvable by the BIND server even after the delegation has been removed from the parent DNS zone.