CVE-2006-0987
published 2006-03-03CVE-2006-0987: The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation…
PriorityP434medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
57.26%
99.0th percentile
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.4.0-1 (bookworm) | bind9 1:9.4.0-1 (bookworm) |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.4.0-1 | 1:9.4.0-1 |
| isc | bind9 | >= 0 < 1:9.4.0-1 | 1:9.4.0-1 |
| isc | bind9 | >= 0 < 1:9.4.0-1 | 1:9.4.0-1 |
| isc | bind9 | >= 0 < 1:9.4.0-1 | 1:9.4.0-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →DNS amplification attack vector: detect recursive DNS queries sent to open resolvers with spoofed source IP addresses, particularly high-volume query patterns indicative of traffic amplification abuse. ↗
- →Use the Metasploit auxiliary module dns_amp to scan for DNS servers exposing recursive name lookups that can be abused in amplification attacks. ↗
- →Audit named.conf for absence of 'allow-query { localhost; };' or equivalent ACL restriction — servers without this restriction accepting queries from arbitrary IPs are vulnerable. ↗
- →A recursive name server should only accept queries from local or authorized clients; any BIND caching nameserver in default config (pre-9.4.1-P1) accepting recursive queries from arbitrary IPs is a candidate for amplification abuse. ↗
- ·ISC BIND versions before 9.4.1-P1 are vulnerable in their default caching nameserver configuration; the fix is present from 9.4.1-P1 onward. ↗
- ·Red Hat Enterprise Linux 5 and 6 ship BIND with 'allow-query { localhost; };' in named.conf by default, making those specific packages NOT vulnerable even without patching. ↗
- ·This vulnerability is inherent to DNS design and cannot be fixed at the protocol level; rate-limiting patches (e.g., from redbarn.org/dns/ratelimits) are the recommended mitigation for non-default configurations. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rmj9-c82h-2f4h: The default configuration of ISC BIND before 9
ghsa_unreviewed·2022-05-01
CVE-2006-0987 [MEDIUM] GHSA-rmj9-c82h-2f4h: The default configuration of ISC BIND before 9
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
OSV
CVE-2006-0987: The default configuration of ISC BIND before 9
osv·2006-03-03·CVSS 5.0
CVE-2006-0987 [MEDIUM] CVE-2006-0987: The default configuration of ISC BIND before 9
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
Red Hat
bind: DDoS (traffic amplification) via DNS queries with spoofed IP addresses due to additional information delegation to arbitrary IP addresses
vendor_redhat·2006-03-03·CVSS 5.0
CVE-2006-0987 [MEDIUM] bind: DDoS (traffic amplification) via DNS queries with spoofed IP addresses due to additional information delegation to arbitrary IP addresses
bind: DDoS (traffic amplification) via DNS queries with spoofed IP addresses due to additional information delegation to arbitrary IP addresses
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
Statement: Not vulnerable. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 5 and 6 and version of bind97 as shipped with Red Hat Enterprise Linux 5 as in the default configuration the named service accept DNS queries only from localhost.
Package: bind (Red Hat Enterprise Linux 5) - N
Debian
CVE-2006-0987: bind9 - The default configuration of ISC BIND before 9.4.1-P1, when configured as a cach...
vendor_debian·2006·CVSS 5.0
CVE-2006-0987 [MEDIUM] CVE-2006-0987: bind9 - The default configuration of ISC BIND before 9.4.1-P1, when configured as a cach...
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
Scope: local
bookworm: resolved (fixed in 1:9.4.0-1)
bullseye: resolved (fixed in 1:9.4.0-1)
forky: resolved (fixed in 1:9.4.0-1)
sid: resolved (fixed in 1:9.4.0-1)
trixie: resolved (fixed in 1:9.4.0-1)
No detection rules found.
http://dns.measurement-factory.com/surveys/sum1.htmlhttp://kb.isc.org/article/AA-00269http://www.securityfocus.com/archive/1/426368/100/0/threadedhttp://www.us-cert.gov/reading_room/DNS-recursion121605.pdfhttp://dns.measurement-factory.com/surveys/sum1.htmlhttp://kb.isc.org/article/AA-00269http://www.securityfocus.com/archive/1/426368/100/0/threadedhttp://www.us-cert.gov/reading_room/DNS-recursion121605.pdf
2006-03-03
Published