Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade bindUpgrade bind-utilsUpgrade bind-develUpgrade bind-libbind-develUpgrade bind-sdbUpgrade bind-libsUpgrade bind-chrootUpgrade caching-nameserver | Dec 1, 2016 | Jan 22, 2010 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jan 22, 2010 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 27, 2014 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 22, 2010 |
| Hpux | — | Update BindUpgrade.BIND-UPGRADE to the latest versionUpdate BINDv920.INETSVCS-BIND to the latest versionApply patch PHNE_40339 from HPUpdate BindUpgrade.BIND2-UPGRADE to the latest version | Aug 11, 2017 | Jan 22, 2010 |
| Oracle_linux | — | Upgrade bind-sdbUpgrade caching-nameserverUpgrade bind-libsUpgrade bind-chrootUpgrade bind-libbind-develUpgrade bind-utilsUpgrade bind-develUpgrade bind | Oct 16, 2024 | Jan 22, 2010 |
| Suse | — | Upgrade bind-docUpgrade bind-libs-x86Upgrade bind-libsUpgrade bindUpgrade bind-utilsUpgrade bind-libs-32bitUpgrade bind-chrootenv | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libdns46Upgrade libdns36Upgrade libdns53Upgrade libdns23Upgrade libdns44 | Nov 8, 2024 | Jan 22, 2010 |
| Vmsa 2010 0009 1 Service Console Package Bind | — | Upgrade VMware ESX 4.0 to build number 256968 | Sep 2, 2010 | Jan 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub