cbcvebase.
CVE-1999-0009
published 1998-04-08

CVE-1999-0009: Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

PriorityP342critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
29.01%
98.0th percentile
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

Affected

74 ranges· showing 25
VendorProductVersion rangeFixed in
bsdibsd_os
bsdibsd_os
bsdibsd_os
calderaopenlinux
data_generaldg_ux
data_generaldg_ux
data_generaldg_ux
data_generaldg_ux
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
ibmaix
iscbind
iscbind
iscbind
necasl_ux_4800
netbsdnetbsd
netbsdnetbsd
netbsdnetbsd
netbsdnetbsd

Detection & IOCsextracted from sources · hover to see the quote

  • ·The Snort rule (SID 2100252) targets UDP port 53 only, but both exploit PoCs use TCP/53 (SOCK_STREAM). A UDP-only rule will miss TCP-based exploitation attempts.
  • ·The exploit includes multiple hardcoded return addresses for different BIND versions and Linux/FreeBSD platforms. Detection based solely on return address values will be incomplete; focus on the IQUERY opcode byte pattern instead.
  • ·The exploit supports an 'optimized' mode that changes the dlen calculation and return address used, meaning packet sizes will vary between optimized and non-optimized runs. Size-based detection alone is unreliable.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.