CVE-2006-2073
published 2006-04-27CVE-2006-2073: Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.99%
94.1th percentile
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.3.3-1 (bookworm) | bind9 1:9.3.3-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.3.3-1 | 1:9.3.3-1 |
| isc | bind9 | >= 0 < 1:9.3.3-1 | 1:9.3.3-1 |
| isc | bind9 | >= 0 < 1:9.3.3-1 | 1:9.3.3-1 |
| isc | bind9 | >= 0 < 1:9.3.3-1 | 1:9.3.3-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-2073: bind9 - Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial ...
vendor_debian·2006·CVSS 5.0
CVE-2006-2073 [MEDIUM] CVE-2006-2073: bind9 - Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial ...
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
Scope: local
bookworm: resolved (fixed in 1:9.3.3-1)
bullseye: resolved (fixed in 1:9.3.3-1)
forky: resolved (fixed in 1:9.3.3-1)
sid: resolved (fixed in 1:9.3.3-1)
trixie: resolved (fixed in 1:9.3.3-1)
Red Hat
CVE-2006-2073: Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstr
vendor_redhat·CVSS 5.0
CVE-2006-2073 [MEDIUM] CVE-2006-2073: Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstr
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
Statement: This issue did not affect the version of bind as shipped with Red Hat Enterprise Linux 5. We do not believe this issue has a security consequence for earlier versions of Red Hat Enterprise Linux. For details please see
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=192192
GHSA
GHSA-35jh-g8qg-jgf5: Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstr
ghsa_unreviewed·2022-05-01
CVE-2006-2073 [MEDIUM] GHSA-35jh-g8qg-jgf5: Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstr
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
OSV
CVE-2006-2073: Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstr
osv·2006-04-27·CVSS 5.0
CVE-2006-2073 [MEDIUM] CVE-2006-2073: Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstr
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/19808http://securitytracker.com/id?1015993http://www.kb.cert.org/vuls/id/955777http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html?lang=enhttp://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=enhttp://www.securityfocus.com/bid/17692http://www.vupen.com/english/advisories/2006/1505http://www.vupen.com/english/advisories/2006/1537https://exchange.xforce.ibmcloud.com/vulnerabilities/26081http://secunia.com/advisories/19808http://securitytracker.com/id?1015993http://www.kb.cert.org/vuls/id/955777http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html?lang=enhttp://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=enhttp://www.securityfocus.com/bid/17692http://www.vupen.com/english/advisories/2006/1505http://www.vupen.com/english/advisories/2006/1537https://exchange.xforce.ibmcloud.com/vulnerabilities/26081
2006-04-27
Published