Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.100831
Category:Denial of Service
Title:ISC BIND Denial Of Service and Security Bypass Vulnerability
Summary:ISC BIND is prone to a security bypass vulnerability and a denial-of-; service vulnerability.
Description:Summary:
ISC BIND is prone to a security bypass vulnerability and a denial-of-
service vulnerability.

Vulnerability Impact:
Successfully exploiting these issues allows remote attackers to crash
affected DNS servers, denying further service to legitimate users, bypass certain security restrictions
and perform unauthorized actions. Other attacks are also possible.

Affected Software/OS:
ISC BIND versions 9.7.2 through 9.7.2-P1 are vulnerable.

Solution:
Vendor updates are available. Please see the references for more
information.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-0218
CERT/CC vulnerability note: VU#784855
http://www.kb.cert.org/vuls/id/784855
https://lists.isc.org/pipermail/bind-announce/2010-September/000655.html
Common Vulnerability Exposure (CVE) ID: CVE-2010-3762
BugTraq ID: 45385
http://www.securityfocus.com/bid/45385
Bugtraq: 20110308 VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm. (Google Search)
http://www.securityfocus.com/archive/1/516909/100/0/threaded
Debian Security Information: DSA-2130 (Google Search)
http://www.debian.org/security/2010/dsa-2130
http://www.mandriva.com/security/advisories?name=MDVSA-2010:253
http://lists.vmware.com/pipermail/security-announce/2011/000126.html
http://www.redhat.com/support/errata/RHSA-2010-0976.html
http://www.vupen.com/english/advisories/2011/0606
CopyrightCopyright (C) 2010 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.