CVE-2005-0034 — Bind vulnerability
6 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
6.6%
top 8.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 1
Description
An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-pmcv-f6x3-9656: An "incorrect assumption" in the authvalidated validator function in BIND 9↗2022-05-01
OSV▶
CVE-2005-0034: An "incorrect assumption" in the authvalidated validator function in BIND 9↗2005-05-02
CVEList▶
CVE-2005-0034: An "incorrect assumption" in the authvalidated validator function in BIND 9↗2005-01-29