ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Apply OS X security update 2011-006Upgrade macOS to the latest version | Aug 28, 2015 | Jan 22, 2010 |
| Apple Osx Bind | — | Apply OS X security update 2011-006 | Dec 16, 2011 | Jan 22, 2010 |
| Centos_linux | — | Upgrade bind-sdbUpgrade caching-nameserverUpgrade bind-libbind-develUpgrade bindUpgrade bind-utilsUpgrade bind-develUpgrade bind-chrootUpgrade bind-libs | Dec 1, 2016 | Jan 22, 2010 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jan 22, 2010 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Oct 5, 2011 | Jan 19, 2010 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 30, 2015 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 22, 2010 |
| Hpux | — | Update BindUpgrade.BIND-UPGRADE to the latest versionUpdate BindUpgrade.BIND2-UPGRADE to the latest versionUpdate NameService.BIND-AUX to the latest versionUpdate NameService.BIND-RUN to the latest version | Aug 11, 2017 | Jan 22, 2010 |
| Ibm Aix | — | Apply the fix or workaround for bind9_advisory3 | Nov 30, 2017 | Jan 22, 2010 |
| Oracle_linux | — | Upgrade bind-chrootUpgrade bind-utilsUpgrade bind-libbind-develUpgrade caching-nameserverUpgrade bindUpgrade bind-sdbUpgrade bind-develUpgrade bind-libs | Oct 16, 2024 | Jan 22, 2010 |
| Suse | — | Upgrade bind-chrootenvUpgrade bind-libsUpgrade bindUpgrade bind-utilsUpgrade bind-docUpgrade bind-libs-32bitUpgrade bind-libs-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libdns44Upgrade libdns36Upgrade libdns23Upgrade libdns53Upgrade libdns46 | Nov 8, 2024 | Jan 22, 2010 |
| Vmsa 2010 0009 1 Service Console Package Bind | — | Upgrade VMware ESX 4.0 to build number 256968 | Sep 2, 2010 | Jan 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub