The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jul 24, 2007 |
| Dns Bind | — | Explicitly set allow-query-cache and allow-recursion acl'sUpgrade ISC BIND to latest version | Oct 5, 2011 | Jul 24, 2007 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jul 24, 2007 |
| Suse | — | Upgrade bind-modules-genericUpgrade bind-modules-ldapUpgrade bind-libs-32bitUpgrade bindUpgrade bind-docUpgrade bind-modules-sqlite3Upgrade bind-develUpgrade bind-devel-32bitUpgrade bind-utilsUpgrade bind-libsUpgrade bind-modules-perlUpgrade bind-modules-mysqlUpgrade bind-chrootenvUpgrade bind-libs-x86 | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub