ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Bind | — | Apply OS X security update 2007-005 | Dec 16, 2011 | Jan 25, 2007 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jan 25, 2007 |
| Dns Bind | — | Disable or restrict recursion & remove DNSSEC validationUpgrade ISC BIND to latest version | Oct 5, 2011 | Jan 25, 2007 |
| Freebsd | — | Upgrade FreeBSDUpgrade named | Dec 10, 2025 | Feb 27, 2007 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 25, 2007 |
| Oracle_linux | — | Upgrade bind-utilsUpgrade bind-develUpgrade bind-libsUpgrade bind-chrootUpgrade bind-libbind-develUpgrade bindUpgrade bind-sdbUpgrade caching-nameserver | Oct 16, 2024 | Jan 25, 2007 |
| Suse | — | Upgrade bind-libs-64bitUpgrade bindUpgrade bind-libsUpgrade suse-releaseUpgrade bind-libs-32bitUpgrade bind-utils | Feb 17, 2015 | Jan 25, 2007 |
| Ubuntu | — | Upgrade libdns20Upgrade libdns21 | Nov 8, 2024 | Jan 25, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub