Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade bind-chrootUpgrade bind-utilsUpgrade caching-nameserverUpgrade bind-develUpgrade bind-libsUpgrade bind-libbind-develUpgrade bind-sdbUpgrade bind | Dec 1, 2016 | Jan 22, 2010 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jan 22, 2010 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 27, 2014 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 22, 2010 |
| Hpux | — | Update BindUpgrade.BIND2-UPGRADE to the latest versionApply patch PHNE_40339 from HPUpdate BindUpgrade.BIND-UPGRADE to the latest versionUpdate BINDv920.INETSVCS-BIND to the latest version | Aug 11, 2017 | Jan 22, 2010 |
| Oracle_linux | — | Upgrade bindUpgrade bind-utilsUpgrade bind-develUpgrade bind-libbind-develUpgrade bind-libsUpgrade caching-nameserverUpgrade bind-sdbUpgrade bind-chroot | Oct 16, 2024 | Jan 22, 2010 |
| Suse | — | Upgrade bind-chrootenvUpgrade bind-utilsUpgrade bindUpgrade bind-libs-32bitUpgrade bind-libsUpgrade bind-docUpgrade bind-libs-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libdns46Upgrade libdns53Upgrade libdns36Upgrade libdns23Upgrade libdns44 | Nov 8, 2024 | Jan 22, 2010 |
| Vmsa 2010 0009 1 Service Console Package Bind | — | Upgrade VMware ESX 4.0 to build number 256968 | Sep 2, 2010 | Jan 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub