CVE-2006-4095
published 2006-09-06CVE-2006-4095: BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion…
PriorityP433high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
12.55%
95.8th percentile
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.3.9 | 10.3.9 |
| apple | mac_os_x | >= 10.4.0 < 10.4.9 | 10.4.9 |
| apple | mac_os_x_server | < 10.3.9 | 10.3.9 |
| apple | mac_os_x_server | >= 10.4.0 < 10.4.9 | 10.4.9 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.3.2-P1-1 (bookworm) | bind9 1:9.3.2-P1-1 (bookworm) |
| isc | bind | <= 9.2.6 | — |
| isc | bind | 9.3.0 – 9.3.2 | — |
| isc | bind9 | >= 0 < 1:9.3.2-P1-1 | 1:9.3.2-P1-1 |
| isc | bind9 | >= 0 < 1:9.3.2-P1-1 | 1:9.3.2-P1-1 |
| isc | bind9 | >= 0 < 1:9.3.2-P1-1 | 1:9.3.2-P1-1 |
| isc | bind9 | >= 0 < 1:9.3.2-P1-1 | 1:9.3.2-P1-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vp8-cx5p-gwx4: BIND before 9
ghsa_unreviewed·2022-05-01
CVE-2006-4095 [MEDIUM] CWE-617 GHSA-4vp8-cx5p-gwx4: BIND before 9
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
OSV
CVE-2006-4095: BIND before 9
osv·2006-09-06·CVSS 7.5
CVE-2006-4095 [HIGH] CVE-2006-4095: BIND before 9
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Ubuntu
bind9 vulnerabilities
vendor_ubuntu·2006-09-08
CVE-2006-4096 bind9 vulnerabilities
Title: bind9 vulnerabilities
Summary: bind9 vulnerabilities
bind did not sufficiently verify particular requests and responses
from other name servers and users. By sending a specially crafted
packet, a remote attacker could exploit this to crash the name server.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
BSD
FreeBSD-SA-06:20.bind: Denial of Service in named(8)
bsd_advisories·2006-09-06·CVSS 7.5
CVE-2006-4095 [HIGH] FreeBSD-SA-06:20.bind: Denial of Service in named(8)
FreeBSD-SA-06:20.bind Security Advisory
The FreeBSD Project
Topic: Denial of Service in named(8)
Category: contrib
Module: bind
Announced: 2006-09-06
Credits: The Measurement Factory
Affects: FreeBSD 5.3 and later.
Corrected: 2006-09-06 21:18:26 UTC (RELENG_6, 6.1-STABLE)
2006-09-06 21:19:21 UTC (RELENG_6_1, 6.1-RELEASE-p6)
2006-09-06 21:20:08 UTC (RELENG_6_0, 6.0-RELEASE-p11)
2006-09-06 21:20:54 UTC (RELENG_5, 5.5-STABLE)
2006-09-06 21:21:50 UTC (RELENG_5_5, 5.5-RELEASE-p4)
2006-09-06 21:22:39 UTC (RELENG_5_4, 5.4-RELEASE-p18)
2006-09-06 21:23:16 UTC (RELENG_5_3, 5.3-RELEASE-p33)
CVE Name: CVE-2006-4095, CVE-2006-4096
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit
.
Debian
CVE-2006-4095: bind9 - BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause ...
vendor_debian·2006·CVSS 7.5
CVE-2006-4095 [HIGH] CVE-2006-4095: bind9 - BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause ...
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Scope: local
bookworm: resolved (fixed in 1:9.3.2-P1-1)
bullseye: resolved (fixed in 1:9.3.2-P1-1)
forky: resolved (fixed in 1:9.3.2-P1-1)
sid: resolved (fixed in 1:9.3.2-P1-1)
trixie: resolved (fixed in 1:9.3.2-P1-1)
Red Hat
CVE-2006-4095: BIND before 9
vendor_redhat·CVSS 7.5
CVE-2006-4095 [HIGH] CVE-2006-4095: BIND before 9
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Statement: Not Vulnerable. The version of BIND that ships with Red Hat Enterprise Linux is not vulnerable to this issue as it does not handle signed RR records.
No detection rules found.
No public exploits indexed.
http://docs.info.apple.com/article.html?artnum=305530http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://secunia.com/advisories/21752http://secunia.com/advisories/21786http://secunia.com/advisories/21816http://secunia.com/advisories/21818http://secunia.com/advisories/21828http://secunia.com/advisories/21835http://secunia.com/advisories/21838http://secunia.com/advisories/21912http://secunia.com/advisories/21926http://secunia.com/advisories/22298http://secunia.com/advisories/24950http://secunia.com/advisories/25402http://security.freebsd.org/advisories/FreeBSD-SA-06:20.bind.aschttp://security.gentoo.org/glsa/glsa-200609-11.xmlhttp://securitytracker.com/id?1016794http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.481241http://www.kb.cert.org/vuls/id/915404http://www.mandriva.com/security/advisories?name=MDKSA-2006:163http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=enhttp://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_24_sr.htmlhttp://www.openbsd.org/errata.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2006.019.htmlhttp://www.securityfocus.com/archive/1/445600/100/0/threadedhttp://www.securityfocus.com/bid/19859http://www.ubuntu.com/usn/usn-343-1http://www.us.debian.org/security/2006/dsa-1172http://www.vupen.com/english/advisories/2006/3473http://www.vupen.com/english/advisories/2007/1401http://www.vupen.com/english/advisories/2007/1939https://exchange.xforce.ibmcloud.com/vulnerabilities/28745https://issues.rpath.com/browse/RPL-626https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144http://docs.info.apple.com/article.html?artnum=305530http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://secunia.com/advisories/21752http://secunia.com/advisories/21786http://secunia.com/advisories/21816http://secunia.com/advisories/21818http://secunia.com/advisories/21828http://secunia.com/advisories/21835http://secunia.com/advisories/21838http://secunia.com/advisories/21912http://secunia.com/advisories/21926http://secunia.com/advisories/22298http://secunia.com/advisories/24950http://secunia.com/advisories/25402http://security.freebsd.org/advisories/FreeBSD-SA-06:20.bind.aschttp://security.gentoo.org/glsa/glsa-200609-11.xmlhttp://securitytracker.com/id?1016794http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.481241http://www.kb.cert.org/vuls/id/915404http://www.mandriva.com/security/advisories?name=MDKSA-2006:163http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=enhttp://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_24_sr.htmlhttp://www.openbsd.org/errata.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2006.019.htmlhttp://www.securityfocus.com/archive/1/445600/100/0/threadedhttp://www.securityfocus.com/bid/19859http://www.ubuntu.com/usn/usn-343-1http://www.us.debian.org/security/2006/dsa-1172http://www.vupen.com/english/advisories/2006/3473http://www.vupen.com/english/advisories/2007/1401http://www.vupen.com/english/advisories/2007/1939https://exchange.xforce.ibmcloud.com/vulnerabilities/28745https://issues.rpath.com/browse/RPL-626https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144
2006-09-06
Published