named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Dec 6, 2010 |
| Dns Bind | — | allow-query acl in each zone statementUpgrade ISC BIND to latest version | Oct 5, 2011 | Dec 1, 2010 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Dec 6, 2010 |
| Suse | — | Upgrade python-bindUpgrade libisc166-32bitUpgrade bind-libs-32bitUpgrade bind-utilsUpgrade bind-docUpgrade liblwres160Upgrade bind-modules-perlUpgrade bind-modules-ldapUpgrade libdns169Upgrade bindUpgrade bind-develUpgrade libbind9-160Upgrade bind-chrootenvUpgrade bind-modules-genericUpgrade libirs160Upgrade libisc166Upgrade bind-modules-sqlite3Upgrade bind-modules-mysqlUpgrade libirs-develUpgrade python3-bindUpgrade libisccc160Upgrade bind-libsUpgrade libisccfg160 | Aug 9, 2024 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub