Description
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-qwch-fhfg-fr39: BIND before 9↗2022-05-01 ▶ CVEListCVE-2006-4096: BIND before 9↗2006-09-06 ▶ OSVCVE-2006-4096: BIND before 9↗2006-09-06 ▶ 📋Vendor Advisories
4Ubuntubind9 vulnerabilities↗2006-09-08 ▶ BSDFreeBSD-SA-06:20.bind: Denial of Service in named(8)↗2006-09-06 ▶ Red HatINSIST failure in ISC BIND recursive query↗2006-09-05 ▶ DebianCVE-2006-4096: bind9 - BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause ...↗2006 ▶ 💬Community
3BugzillaCVE-2006-4096 INSIST failure in ISC BIND recursive query↗2009-04-07 ▶ BugzillaCVE-2006-5823 corrupted cramfs crashes in zlib_inflate↗2006-10-20 ▶ BugzillaCVE-2006-1864 smbfs chroot issue↗2006-04-19 ▶