Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Apply OS X security update 2011-006Upgrade macOS to the latest version | Aug 28, 2015 | Nov 25, 2009 |
| Apple Osx Bind | — | Apply OS X security update 2011-006 | Dec 16, 2011 | Nov 25, 2009 |
| Centos_linux | — | Upgrade bind-libsUpgrade bind-utilsUpgrade bind-libbind-develUpgrade bind-sdbUpgrade bind-chrootUpgrade caching-nameserverUpgrade bindUpgrade bind-devel | Dec 1, 2016 | Nov 25, 2009 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Nov 25, 2009 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 3, 2013 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Nov 25, 2009 |
| Hpux | — | Update BindUpgrade.BIND2-UPGRADE to the latest versionApply patch PHNE_40339 from HPUpdate BindUpgrade.BIND-UPGRADE to the latest versionUpdate BINDv920.INETSVCS-BIND to the latest version | Aug 11, 2017 | Nov 25, 2009 |
| Ibm Aix | — | Apply the fix or workaround for bind9_advisory | Nov 30, 2017 | Nov 25, 2009 |
| Oracle_linux | — | Upgrade bind-utilsUpgrade bind-libsUpgrade bind-develUpgrade bind-chrootUpgrade bind-libbind-develUpgrade bind-sdbUpgrade bindUpgrade caching-nameserver | Oct 16, 2024 | Nov 25, 2009 |
| Suse | — | Upgrade libirs160Upgrade bindUpgrade bind-modules-genericUpgrade bind-utilsUpgrade libirs-develUpgrade bind-modules-mysqlUpgrade bind-modules-perlUpgrade bind-chrootenvUpgrade bind-modules-sqlite3Upgrade bind-libs-32bitUpgrade bind-develUpgrade bind-devel-32bitUpgrade libisccc160Upgrade bind-libsUpgrade bind-modules-ldapUpgrade libisc166Upgrade python3-bindUpgrade python-bindUpgrade bind-docUpgrade libdns169Upgrade bind-libs-x86Upgrade libisc166-32bitUpgrade libbind9-160Upgrade libisccfg160Upgrade liblwres160 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libdns23Upgrade libdns36Upgrade libdns44Upgrade libdns46Upgrade libdns53 | Nov 8, 2024 | Nov 25, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub