CVE-2006-0527Bind vulnerability

CWE-2643 documents3 sources
Severity
7.5HIGHNVD
EPSS
7.1%
top 8.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 2
Latest updateMay 1

Description

BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDisc/bind4, 8+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q2rh-q7xj-6gw7: BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache2022-05-01
CVEList
CVE-2006-0527: BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache2006-02-02
CVE-2006-0527 — ISC Bind vulnerability | cvebase