[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-1033Date: (C)2012-02-08   (M)2023-12-22


The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1026647
SECUNIA-47884
BID-51898
OSVDB-78916
RHSA-2012:0717
SSRT100763
VU#542123
https://www.isc.org/software/bind/advisories/cve-2012-1033
isc-bind-update-sec-bypass(73053)
openSUSE-SU-2012:0863
openSUSE-SU-2012:0864

CPE    72
cpe:/a:isc:bind:9.7.2:p2
cpe:/a:isc:bind:9.7.2:p3
cpe:/a:isc:bind:9.7.2:p1
cpe:/a:isc:bind:9.8.1:p1
...
OVAL    9
oval:org.secpod.oval:def:700880
oval:org.secpod.oval:def:202350
oval:org.secpod.oval:def:202352
oval:org.secpod.oval:def:202351
...

© SecPod Technologies