CVE-2009-0696

PUBLISHED

The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as...

ISC · BIND

Recommended Action

Track for updates. Assess relevance to your asset inventory and enrichment workflows.

Confidence
Exploitation Status
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
CVSS / EPSS
4.3 Medium

At a Glance

The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message.

CVE Published
Jul 29, 2009
CVSS
4.3 Medium
EPSS
Remote Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 36035 secunia.com · CVE Record http://secunia.com/advisories/36035
  • 36063 secunia.com · CVE Record http://secunia.com/advisories/36063
  • ADV-2009-2171 vupen.com · CVE Record http://www.vupen.com/english/advisories/2009/2171
  • 36056 secunia.com · CVE Record http://secunia.com/advisories/36056
  • 36038 secunia.com · CVE Record http://secunia.com/advisories/36038
Show 32 more references

Recommended Actions

  • Track for updates. Assess relevance to your asset inventory and enrichment workflows.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.