CVE-2005-0034Bind vulnerability

6 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
6.6%
top 8.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debianisc/bind9< 1:9.3.1+3
NVDisc/bind9.3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pmcv-f6x3-9656: An "incorrect assumption" in the authvalidated validator function in BIND 92022-05-01
OSV
CVE-2005-0034: An "incorrect assumption" in the authvalidated validator function in BIND 92005-05-02
CVEList
CVE-2005-0034: An "incorrect assumption" in the authvalidated validator function in BIND 92005-01-29

📋Vendor Advisories

2
BSD
FreeBSD-SA-05:12.bind9: BIND 9 DNSSEC remote denial of service vulnerability2005-06-09
Debian
CVE-2005-0034: bind9 - An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0,...2005
CVE-2005-0034 — ISC Bind vulnerability | cvebase