CVE-2006-4096
published 2006-09-06CVE-2006-4096: BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
8.68%
94.6th percentile
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.3.2-P1-1 (bookworm) | bind9 1:9.3.2-P1-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.3.2-P1-1 | 1:9.3.2-P1-1 |
| isc | bind9 | >= 0 < 1:9.3.2-P1-1 | 1:9.3.2-P1-1 |
| isc | bind9 | >= 0 < 1:9.3.2-P1-1 | 1:9.3.2-P1-1 |
| isc | bind9 | >= 0 < 1:9.3.2-P1-1 | 1:9.3.2-P1-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qwch-fhfg-fr39: BIND before 9
ghsa_unreviewed·2022-05-01
CVE-2006-4096 [MEDIUM] GHSA-qwch-fhfg-fr39: BIND before 9
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
OSV
CVE-2006-4096: BIND before 9
osv·2006-09-06·CVSS 5.0
CVE-2006-4096 [MEDIUM] CVE-2006-4096: BIND before 9
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
Ubuntu
bind9 vulnerabilities
vendor_ubuntu·2006-09-08
CVE-2006-4096 bind9 vulnerabilities
Title: bind9 vulnerabilities
Summary: bind9 vulnerabilities
bind did not sufficiently verify particular requests and responses
from other name servers and users. By sending a specially crafted
packet, a remote attacker could exploit this to crash the name server.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
BSD
FreeBSD-SA-06:20.bind: Denial of Service in named(8)
bsd_advisories·2006-09-06·CVSS 7.5
CVE-2006-4095 [HIGH] FreeBSD-SA-06:20.bind: Denial of Service in named(8)
FreeBSD-SA-06:20.bind Security Advisory
The FreeBSD Project
Topic: Denial of Service in named(8)
Category: contrib
Module: bind
Announced: 2006-09-06
Credits: The Measurement Factory
Affects: FreeBSD 5.3 and later.
Corrected: 2006-09-06 21:18:26 UTC (RELENG_6, 6.1-STABLE)
2006-09-06 21:19:21 UTC (RELENG_6_1, 6.1-RELEASE-p6)
2006-09-06 21:20:08 UTC (RELENG_6_0, 6.0-RELEASE-p11)
2006-09-06 21:20:54 UTC (RELENG_5, 5.5-STABLE)
2006-09-06 21:21:50 UTC (RELENG_5_5, 5.5-RELEASE-p4)
2006-09-06 21:22:39 UTC (RELENG_5_4, 5.4-RELEASE-p18)
2006-09-06 21:23:16 UTC (RELENG_5_3, 5.3-RELEASE-p33)
CVE Name: CVE-2006-4095, CVE-2006-4096
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit
.
Red Hat
INSIST failure in ISC BIND recursive query
vendor_redhat·2006-09-05·CVSS 5.0
CVE-2006-4096 [MEDIUM] INSIST failure in ISC BIND recursive query
INSIST failure in ISC BIND recursive query
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
Statement: This issue does not affect Red Hat Enterprise Linux 2.1
Debian
CVE-2006-4096: bind9 - BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause ...
vendor_debian·2006·CVSS 5.0
CVE-2006-4096 [MEDIUM] CVE-2006-4096: bind9 - BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause ...
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
Scope: local
bookworm: resolved (fixed in 1:9.3.2-P1-1)
bullseye: resolved (fixed in 1:9.3.2-P1-1)
forky: resolved (fixed in 1:9.3.2-P1-1)
sid: resolved (fixed in 1:9.3.2-P1-1)
trixie: resolved (fixed in 1:9.3.2-P1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4096 INSIST failure in ISC BIND recursive query
bugzilla·2009-04-07·CVSS 5.0
CVE-2006-4096 [MEDIUM] CVE-2006-4096 INSIST failure in ISC BIND recursive query
CVE-2006-4096 INSIST failure in ISC BIND recursive query
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to
cause a denial of service (crash) via a flood of recursive queries, which
cause an INSIST failure when the response is received after the recursion
queue is empty.
Discussion:
Created attachment 338495
Patch for this issue
---
This is fixed in Red Hat Enterprise Linux 3 and 4 by the patch
bind-9.2.4-bz173961.patch
It was fixed in the errata RHBA-2006:0287 and RHBA-2006:0288.
They are not marked as RHSA errata as the patch went in before it was recognized as being a security relevant fix. The errata do however note the CVE id in question.
---
The technical details about fix this flaw can found in bug 173961
Specifically comment #21
Bugzilla
CVE-2006-5823 corrupted cramfs crashes in zlib_inflate
bugzilla·2006-10-20·CVSS 4.0
CVE-2006-5823 [MEDIUM] CVE-2006-5823 corrupted cramfs crashes in zlib_inflate
CVE-2006-5823 corrupted cramfs crashes in zlib_inflate
Oct 19 10:38:17 localhost kernel: Error -3 while decompressing!
Oct 19 10:38:17 localhost kernel:
ffffffff8852d146(-1711276009)->ffff810033dad000(4096)
Oct 19 10:38:17 localhost kernel: Unable to handle kernel paging request at
000000002252d15d RIP:
Oct 19 10:38:17 localhost kernel: [] zlib_inflate+0x110/0x15f1
Oct 19 10:38:17 localhost kernel: PGD 366eb067 PUD 36002067 PMD 0
Oct 19 10:38:17 localhost kernel: Oops: 0000 [1] SMP
Oct 19 10:38:17 localhost kernel: last sysfs file: /block/loop4/range
Oct 19 10:38:17 localhost kernel: CPU 0
Oct 19 10:38:17 localhost kernel: Modules linked in: cramfs loop ipv6 autofs4
hidp rfcomm l2cap bluetooth sunrpc ipt_REJECT xt_state ip_conntrack nfnetlink
xt_tcpudp iptable_filter ip_tables x_tables dm
Bugzilla
CVE-2006-1864 smbfs chroot issue
bugzilla·2006-04-19·CVSS 4.6
CVE-2006-1864 [MEDIUM] CVE-2006-1864 smbfs chroot issue
CVE-2006-1864 smbfs chroot issue
When doing a chroot inside of a smb-mounted filesystem (cifs), it appears that
you can break out of it using "cd ..\\" (2 backslashes).
[root@server me]# pwd
/path/to/my/dir
[root@server me]# ls
bin chroot etc lib
[root@server me]# chroot .
bash-2.05a# pwd
/
bash-2.05a# ls
bin chroot etc lib
bash-2.05a# cd ..\\
bash-2.05a# pwd
/..\
bash-2.05a# ls
Discussion:
Fix verified:
.qa.[root@i386-21as-bos tmp]# ll
total 2568
drwxr-xr-x 2 root root 4096 Jul 12 11:50 backup
-rw-r--r-- 1 root root 768000 Jul 12 11:42 bak.file
drwxr-xr-x 2 root root 4096 Jun 4 01:38 bin
drwxr-xr-x 2 root root 4096 Jul 12 08:37 dumper
-rw-r--r-- 1 root root 1048576 Jul 12 09:50 dumpy.iso
drwxr-xr-x 72 root root 8192 Jul 12 11:58 etc
-rw-r--r-- 1 root root 768000 Jul 12 11:21 file.dum
http://docs.info.apple.com/article.html?artnum=305530http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://marc.info/?l=bugtraq&m=141879471518471&w=2http://secunia.com/advisories/21752http://secunia.com/advisories/21786http://secunia.com/advisories/21790http://secunia.com/advisories/21816http://secunia.com/advisories/21818http://secunia.com/advisories/21828http://secunia.com/advisories/21835http://secunia.com/advisories/21838http://secunia.com/advisories/21912http://secunia.com/advisories/21926http://secunia.com/advisories/22298http://secunia.com/advisories/24950http://secunia.com/advisories/25402http://security.freebsd.org/advisories/FreeBSD-SA-06:20.bind.aschttp://security.gentoo.org/glsa/glsa-200609-11.xmlhttp://securitytracker.com/id?1016794http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.481241http://www-1.ibm.com/support/docview.wss?uid=isg1IY89169http://www-1.ibm.com/support/docview.wss?uid=isg1IY89178http://www.kb.cert.org/vuls/id/697164http://www.mandriva.com/security/advisories?name=MDKSA-2006:163http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=enhttp://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_24_sr.htmlhttp://www.openbsd.org/errata.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2006.019.htmlhttp://www.securityfocus.com/archive/1/445600/100/0/threadedhttp://www.securityfocus.com/bid/19859http://www.ubuntu.com/usn/usn-343-1http://www.us.debian.org/security/2006/dsa-1172http://www.vupen.com/english/advisories/2006/3473http://www.vupen.com/english/advisories/2006/3511http://www.vupen.com/english/advisories/2007/1401http://www.vupen.com/english/advisories/2007/1939https://exchange.xforce.ibmcloud.com/vulnerabilities/28744https://issues.rpath.com/browse/RPL-626https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9623https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144http://docs.info.apple.com/article.html?artnum=305530http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://marc.info/?l=bugtraq&m=141879471518471&w=2http://secunia.com/advisories/21752http://secunia.com/advisories/21786http://secunia.com/advisories/21790http://secunia.com/advisories/21816http://secunia.com/advisories/21818http://secunia.com/advisories/21828http://secunia.com/advisories/21835http://secunia.com/advisories/21838http://secunia.com/advisories/21912http://secunia.com/advisories/21926http://secunia.com/advisories/22298http://secunia.com/advisories/24950http://secunia.com/advisories/25402http://security.freebsd.org/advisories/FreeBSD-SA-06:20.bind.aschttp://security.gentoo.org/glsa/glsa-200609-11.xmlhttp://securitytracker.com/id?1016794http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.481241http://www-1.ibm.com/support/docview.wss?uid=isg1IY89169http://www-1.ibm.com/support/docview.wss?uid=isg1IY89178http://www.kb.cert.org/vuls/id/697164http://www.mandriva.com/security/advisories?name=MDKSA-2006:163http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=enhttp://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_24_sr.htmlhttp://www.openbsd.org/errata.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2006.019.htmlhttp://www.securityfocus.com/archive/1/445600/100/0/threadedhttp://www.securityfocus.com/bid/19859http://www.ubuntu.com/usn/usn-343-1http://www.us.debian.org/security/2006/dsa-1172http://www.vupen.com/english/advisories/2006/3473http://www.vupen.com/english/advisories/2006/3511http://www.vupen.com/english/advisories/2007/1401http://www.vupen.com/english/advisories/2007/1939https://exchange.xforce.ibmcloud.com/vulnerabilities/28744https://issues.rpath.com/browse/RPL-626https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9623https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144
2006-09-06
Published