5
CVSSv2

CVE-2006-0987

Published: 03/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 515
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The default configuration of ISC BIND prior to 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote malicious users to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 9.3.2

Vendor Advisories

Debian Bug report logs - #355787 bind: default config allows recursive queries which could allows remote attackers to cause a DoS Package: bind9; Maintainer for bind9 is Debian DNS Team <team+dns@trackerdebianorg>; Source for bind9 is src:bind9 (PTS, buildd, popcon) Reported by: SALVETTI Djoume <djoume@taketorg> D ...

Nmap Scripts

vulners

For each available CPE the script prints out known vulns (links to the correspondent info) and correspondent CVSS scores.

nmap -sV --script vulners [--script-args mincvss=<arg_val>] <target>

53/tcp open domain ISC BIND DNS | vulners: | ISC BIND DNS: | CVE-2012-1667 8.5 https://vulners.com/cve/CVE-2012-1667 | CVE-2002-0651 7.5 https://vulners.com/cve/CVE-2002-0651 | CVE-2002-0029 7.5 https://vulners.com/cve/CVE-2002-0029 | CVE-2015-5986 7.1 https://vulners.com/cve/CVE-2015-5986 | CVE-2010-3615 5.0 https://vulners.com/cve/CVE-2010-3615 | CVE-2006-0987 5.0 https://vulners.com/cve/CVE-2006-0987 |_ CVE-2014-3214 5.0 https://vulners.com/cve/CVE-2014-3214