ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade bind-utilsUpgrade bind-libsUpgrade caching-nameserverUpgrade bindUpgrade bind-sdbUpgrade bind-chrootUpgrade bind-libbind-develUpgrade bind-devel | Dec 1, 2016 | Jan 22, 2010 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jan 22, 2010 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 3, 2014 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 22, 2010 |
| Hpux | — | Apply patch PHNE_40339 from HPUpdate BindUpgrade.BIND2-UPGRADE to the latest versionUpdate BindUpgrade.BIND-UPGRADE to the latest versionUpdate BINDv920.INETSVCS-BIND to the latest version | Aug 11, 2017 | Jan 22, 2010 |
| Ibm Aix | — | Apply the fix or workaround for bind9_advisory3 | Nov 30, 2017 | Jan 22, 2010 |
| Oracle_linux | — | Upgrade bind-develUpgrade bind-utilsUpgrade bind-libsUpgrade bind-chrootUpgrade bindUpgrade bind-libbind-develUpgrade caching-nameserverUpgrade bind-sdb | Oct 16, 2024 | Jan 22, 2010 |
| Ubuntu | — | Upgrade bind9 | Nov 19, 2024 | Jan 22, 2010 |
| Vmsa 2010 0009 1 Service Console Package Bind | — | Upgrade VMware ESX 4.0 to build number 256968 | Sep 2, 2010 | Jan 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub