[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-4095Date: (C)2006-09-05   (M)2024-02-23


BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score : 5.0
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: PARTIAL
Integrity: NONE 
Availability: HIGH 
  
Reference:
SECTRACK-1016794
BID-19859
http://www.securityfocus.com/archive/1/445600/100/0/threaded
SECUNIA-21752
SECUNIA-21786
SECUNIA-21816
SECUNIA-21818
SECUNIA-21828
SECUNIA-21835
SECUNIA-21838
SECUNIA-21912
SECUNIA-21926
SECUNIA-22298
SECUNIA-24950
SECUNIA-25402
ADV-2006-3473
ADV-2007-1401
ADV-2007-1939
APPLE-SA-2007-05-24
DSA-1172
FreeBSD-SA-06:20.bind
GLSA-200609-11
MDKSA-2006:163
OpenPKG-SA-2006.019
SSA:2006-257-01
SSRT071304
SUSE-SR:2006:023
SUSE-SR:2006:024
USN-343-1
VU#915404
http://www.openbsd.org/errata.html
bind-dnssec-rrset-dos(28745)
http://docs.info.apple.com/article.html?artnum=305530
http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=en
https://issues.rpath.com/browse/RPL-626

CWE    1
CWE-617

© SecPod Technologies