7.6
CVSSv2

CVE-2010-0382

Published: 22/01/2010 Updated: 19/09/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 678
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

ISC BIND 9.0.x up to and including 9.3.x, 9.4 prior to 9.4.3-P5, 9.5 prior to 9.5.2-P2, 9.6 prior to 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote malicious users to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 9.7.0

isc bind 9.6.1

isc bind 9.6.0

isc bind 9.4.3

isc bind 9.4.1

isc bind 9.4.0

isc bind 9.3.5

isc bind 9.3.2

isc bind 9.3.1

isc bind 9.3.0

isc bind 9.2.7

isc bind 9.2.4

isc bind 9.2.3

isc bind 9.2.2

isc bind 9.2.1

isc bind 9.2.0

isc bind 9.10.3

isc bind 9.10.1

isc bind 9.10.0

isc bind 9.1.3

isc bind 9.1.1

isc bind 9.0.1

isc bind 9.4.2

isc bind 9.4

isc bind 9.3.3

isc bind 9.3

isc bind 9.2.9

isc bind 9.2.6

isc bind 9.2.5

isc bind 9.10.2

isc bind 9.1.2

isc bind 9.1.0

isc bind 9.0.0

isc bind 9.3.4

isc bind 9.2

isc bind 9.3.6

isc bind 9.2.8

isc bind 9.1

isc bind 9.0

Vendor Advisories

Synopsis Moderate: bind security update Type/Severity Security Advisory: Moderate Topic Updated bind packages that fix two security issues are now available forRed Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Description ...
Several cache-poisoning vulnerabilities have been discovered in BIND These vulnerabilities apply only if DNSSEC validation is enabled and trust anchors have been installed, which is not the default The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-0097 BIND does not properly validate DNSSEC NSEC recor ...