CVE-2009-4022
published 2009-11-25CVE-2009-4022: Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with…
PriorityP420low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
7.95%
94.1th percentile
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.7.0.dfsg-1 (bookworm) | bind9 1:9.7.0.dfsg-1 (bookworm) |
| debian | bind9 | < bind9 1:9.6.1.dfsg.P2-1 (bookworm) | bind9 1:9.6.1.dfsg.P2-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_debian2.6MEDIUM
vendor_redhat2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2010-01-20·CVSS 2.6
CVE-2010-0097 [LOW] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind vulnerabilities
It was discovered that Bind would incorrectly cache bogus NXDOMAIN
responses. When DNSSEC validation is in use, a remote attacker could
exploit this to cause a denial of service, and possibly poison DNS caches.
(CVE-2010-0097)
USN-865-1 provided updated Bind packages to fix a security vulnerability.
The upstream security patch to fix CVE-2009-4022 was incomplete and
CVE-2010-0290 was assigned to the issue. This update corrects the problem.
Original advisory details:
Michael Sinatra discovered that Bind did not correctly validate certain
records added to its cache. When DNSSEC validation is in use, a remote
attacker could exploit this to spoof DNS entries and poison DNS caches.
Among other things, this could lead to misdirected e
Red Hat
BIND upstream fix for CVE-2009-4022 is incomplete
vendor_redhat·2010-01-19·CVSS 2.6
CVE-2010-0290 [LOW] BIND upstream fix for CVE-2009-4022 is incomplete
BIND upstream fix for CVE-2009-4022 is incomplete
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
Red Hat
bind: out-of-bailiwick data vulnerability due to regression while fixing CVE-2009-4022
vendor_redhat·2010-01-19·CVSS 2.6
CVE-2010-0382 [LOW] bind: out-of-bailiwick data vulnerability due to regression while fixing CVE-2009-4022
bind: out-of-bailiwick data vulnerability due to regression while fixing CVE-2009-4022
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.
BSD
FreeBSD-SA-10:01.bind: BIND named(8) cache poisoning with DNSSEC validation
bsd_advisories·2010-01-06·CVSS 2.6
CVE-2009-4022 [LOW] FreeBSD-SA-10:01.bind: BIND named(8) cache poisoning with DNSSEC validation
FreeBSD-SA-10:01.bind Security Advisory
The FreeBSD Project
Topic: BIND named(8) cache poisoning with DNSSEC validation
Category: contrib
Module: bind
Announced: 2010-01-06
Credits: Michael Sinatra
Affects: All supported versions of FreeBSD.
Corrected: 2009-12-11 01:23:58 UTC (RELENG_8, 8.0-STABLE)
2010-01-06 21:45:30 UTC (RELENG_8_0, 8.0-RELEASE-p2)
2009-12-11 02:23:04 UTC (RELENG_7, 7.2-STABLE)
2010-01-06 21:45:30 UTC (RELENG_7_2, 7.2-RELEASE-p6)
2010-01-06 21:45:30 UTC (RELENG_7_1, 7.1-RELEASE-p10)
2010-01-06 21:45:30 UTC (RELENG_6, 6.4-STABLE)
2010-01-06 21:45:30 UTC (RELENG_6_4, 6.4-RELEASE-p9)
2010-01-06 21:45:30 UTC (RELENG_6_3, 6.3-RELEASE-p15)
CVE Name: CVE-2009-4022
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, secur
Debian
CVE-2010-0382: bind9 - ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 befo...
vendor_debian·2010·CVSS 2.6
CVE-2010-0382 [LOW] CVE-2010-0382: bind9 - ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 befo...
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.
Scope: local
bookworm: resolved (fixed in 1:9.7.0.dfsg-1)
bullseye: resolved (fixed in 1:9.7.0.dfsg-1)
forky: resolved (fixed in 1:9.7.0.dfsg-1)
sid: resolved (fixed in 1:9.7.0.dfsg-1)
trixie: resolved (fixed in 1:9.7.0.dfsg-1)
Debian
CVE-2010-0290: bind9 - Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, ...
vendor_debian·2010·CVSS 2.6
CVE-2010-0290 [LOW] CVE-2010-0290: bind9 - Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, ...
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
Scope: local
bookworm: resolved (fixed in 1:9.7.0.dfsg-1)
bullseye: resolved (fixed in 1:9.7.0.dfsg-1)
forky: resolved (fixed in 1:9.7.0.dfsg-1)
sid: resolved (fixed in 1:9.7.0.dfsg-1)
trixie: resolved (fixed in 1:9.7.0.dfsg-1)
Ubuntu
Bind vulnerability
vendor_ubuntu·2009-12-07
CVE-2009-4022 Bind vulnerability
Title: Bind vulnerability
Summary: Bind vulnerability
Michael Sinatra discovered that Bind did not correctly validate certain
records added to its cache. When DNSSEC validation is in use, a remote
attacker could exploit this to spoof DNS entries and poison DNS caches.
Among other things, this could lead to misdirected email and web traffic.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
bind: cache poisoning using not validated DNSSEC responses
vendor_redhat·2009-11-23·CVSS 2.6
CVE-2009-4022 [LOW] bind: cache poisoning using not validated DNSSEC responses
bind: cache poisoning using not validated DNSSEC responses
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
Statement: While this flaw exists in all 9.x versions, we do not plan to release bind updates for Red Hat Enterprise Linux 3 and 4 including this fix. The version of bind shipped in those products is 9.2.4, which has an
Debian
CVE-2009-4022: bind9 - Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, ...
vendor_debian·2009·CVSS 2.6
CVE-2009-4022 [LOW] CVE-2009-4022: bind9 - Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, ...
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
Scope: local
bookworm: resolved (fixed in 1:9.6.1.dfsg.P2-1)
bullseye: resolved (fixed in 1:9.6.1.dfsg.P2-1)
forky: resolved (fixed in 1:9.6.1.dfsg.P2-1)
sid: resolved (fixed in 1:9.6.1.dfsg.P2-1)
trixie: resolved (fixed in 1:9.6.1.dfsg.P2-1)
GHSA
GHSA-2jw5-w5pg-58h8: Unspecified vulnerability in ISC BIND 9
ghsa_unreviewed·2022-05-03
CVE-2009-4022 [LOW] GHSA-2jw5-w5pg-58h8: Unspecified vulnerability in ISC BIND 9
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
GHSA
GHSA-h2vx-r9q8-wjqr: Unspecified vulnerability in ISC BIND 9
ghsa_unreviewed·2022-05-02·CVSS 2.6
CVE-2010-0290 [LOW] GHSA-h2vx-r9q8-wjqr: Unspecified vulnerability in ISC BIND 9
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
GHSA
GHSA-qjm2-h4v8-qrj8: ISC BIND 9
ghsa_unreviewed·2022-05-02·CVSS 2.6
CVE-2010-0382 [LOW] GHSA-qjm2-h4v8-qrj8: ISC BIND 9
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.
OSV
CVE-2010-0290: Unspecified vulnerability in ISC BIND 9
osv·2010-01-22·CVSS 2.6
CVE-2010-0290 [LOW] CVE-2010-0290: Unspecified vulnerability in ISC BIND 9
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
OSV
CVE-2010-0382: ISC BIND 9
osv·2010-01-22·CVSS 2.6
CVE-2010-0382 [LOW] CVE-2010-0382: ISC BIND 9
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.
OSV
CVE-2009-4022: Unspecified vulnerability in ISC BIND 9
osv·2009-11-25·CVSS 2.6
CVE-2009-4022 [LOW] CVE-2009-4022: Unspecified vulnerability in ISC BIND 9
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0382 bind: out-of-bailiwick data vulnerability due to regression while fixing CVE-2009-4022
bugzilla·2010-01-22·CVSS 2.6
CVE-2010-0382 [LOW] CVE-2010-0382 bind: out-of-bailiwick data vulnerability due to regression while fixing CVE-2009-4022
CVE-2010-0382 bind: out-of-bailiwick data vulnerability due to regression while fixing CVE-2009-4022
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0382 to
the following vulnerability:
Name: CVE-2010-0382
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0382
Assigned: 20100122
Reference: CONFIRM: https://www.isc.org/advisories/CVE-2009-4022v6
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before
9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick
data accompanying a secure response without re-fetching from the
original source, which allows remote attackers to have an unspecified
impact via a crafted response, aka Bug 20819. NOTE: this vulnerability
exists because of a regression during the fix for CVE-2009-4022
Discussion:
I'
Bugzilla
CVE-2010-0290 BIND upstream fix for CVE-2009-4022 is incomplete
bugzilla·2010-01-20·CVSS 2.6
CVE-2010-0290 [LOW] CVE-2010-0290 BIND upstream fix for CVE-2009-4022 is incomplete
CVE-2010-0290 BIND upstream fix for CVE-2009-4022 is incomplete
The original fix for CVE-2009-4022 was found to be incomplete. BIND was incorrectly caching certain responses without performing proper DNSSEC validation. CNAME and DNAME records could be cached, without proper DNSSEC validation, when received from processing recursive client queries that requested DNSSEC records but indicated that checking should be disabled. A remote attacker could use this flaw to bypass the DNSSEC validation check and perform a cache poisoning attack if the target BIND server was receiving such client queries.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0062 https://rhn.redhat.com/errata/RHSA-2010-0062.html
Bugzilla
CVE-2010-0097 BIND DNSSEC NSEC/NSEC3 validation code could cause bogus NXDOMAIN responses
bugzilla·2010-01-12·CVSS 2.6
CVE-2010-0097 [LOW] CVE-2010-0097 BIND DNSSEC NSEC/NSEC3 validation code could cause bogus NXDOMAIN responses
CVE-2010-0097 BIND DNSSEC NSEC/NSEC3 validation code could cause bogus NXDOMAIN responses
We received the following advisory from ISC:
Description:
There was an error in the DNSSEC NSEC/NSEC3 validation code that could
cause bogus NXDOMAIN responses (that is, NXDOMAIN responses for records
proven by NSEC or NSEC3 to exist) to be cached as if they had validated
correctly, so that future queries to the resolver would return the bogus
NXDOMAIN with the AD flag set.
Impact:
This problem affects all DNSSEC-validating resolvers. It would be
difficult to exploit due to other existing protections against cache
poisoning (including transaction ID and source port randomization), but
it could impair the ability of DNSSEC to protect against a
denial-of-service attack on a secure zone.
Workarounds:
Bugzilla
CVE-2009-4022 bind: cache poisoning using not validated DNSSEC responses
bugzilla·2009-11-19·CVSS 2.6
CVE-2009-4022 [LOW] CVE-2009-4022 bind: cache poisoning using not validated DNSSEC responses
CVE-2009-4022 bind: cache poisoning using not validated DNSSEC responses
ISC reports a cache poisoning flaw reported by Michael Sinatra of UC Berkeley that may cause bind to cache replies that were not properly DNSSEC validated when recursive query was done based on uncommon client query.
A nameserver with DNSSEC validation enabled may incorrectly add records
to its cache from the additional section of responses received during
resolution of a recursive client query. This behavior only occurs when
processing client queries with checking disabled (CD) at the same time
as requesting DNSSEC records (DO).
This issue was reported to affect all 9.x versions and should be fixed in 9.4.3-P4, 9.5.2-P1 and 9.6.1-P2.
Discussion:
While this flaw exists in all 9.x versions, we do not plan to relea
ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txthttp://aix.software.ibm.com/aix/efixes/security/bind9_advisory.aschttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://osvdb.org/60493http://secunia.com/advisories/37426http://secunia.com/advisories/37491http://secunia.com/advisories/38219http://secunia.com/advisories/38240http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://secunia.com/advisories/39334http://secunia.com/advisories/40730http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021660.1-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021798.1-1http://support.apple.com/kb/HT5002http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018http://www.ibm.com/support/docview.wss?uid=isg1IZ68597http://www.ibm.com/support/docview.wss?uid=isg1IZ71667http://www.ibm.com/support/docview.wss?uid=isg1IZ71774http://www.kb.cert.org/vuls/id/418861http://www.mandriva.com/security/advisories?name=MDVSA-2009:304http://www.openwall.com/lists/oss-security/2009/11/24/1http://www.openwall.com/lists/oss-security/2009/11/24/2http://www.openwall.com/lists/oss-security/2009/11/24/8http://www.redhat.com/support/errata/RHSA-2009-1620.htmlhttp://www.securityfocus.com/bid/37118http://www.ubuntu.com/usn/USN-888-1http://www.vupen.com/english/advisories/2009/3335http://www.vupen.com/english/advisories/2010/0176http://www.vupen.com/english/advisories/2010/0528http://www.vupen.com/english/advisories/2010/0622https://bugzilla.redhat.com/show_bug.cgi?id=538744https://exchange.xforce.ibmcloud.com/vulnerabilities/54416https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://issues.rpath.com/browse/RPL-3152https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10821https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11745https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7261https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7459https://www.isc.org/advisories/CVE-2009-4022v6https://www.isc.org/advisories/CVE2009-4022https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01172.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg01188.htmlftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txthttp://aix.software.ibm.com/aix/efixes/security/bind9_advisory.aschttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://osvdb.org/60493http://secunia.com/advisories/37426http://secunia.com/advisories/37491http://secunia.com/advisories/38219http://secunia.com/advisories/38240http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://secunia.com/advisories/39334http://secunia.com/advisories/40730http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021660.1-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021798.1-1http://support.apple.com/kb/HT5002http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018http://www.ibm.com/support/docview.wss?uid=isg1IZ68597http://www.ibm.com/support/docview.wss?uid=isg1IZ71667http://www.ibm.com/support/docview.wss?uid=isg1IZ71774http://www.kb.cert.org/vuls/id/418861http://www.mandriva.com/security/advisories?name=MDVSA-2009:304http://www.openwall.com/lists/oss-security/2009/11/24/1http://www.openwall.com/lists/oss-security/2009/11/24/2http://www.openwall.com/lists/oss-security/2009/11/24/8http://www.redhat.com/support/errata/RHSA-2009-1620.htmlhttp://www.securityfocus.com/bid/37118http://www.ubuntu.com/usn/USN-888-1http://www.vupen.com/english/advisories/2009/3335http://www.vupen.com/english/advisories/2010/0176http://www.vupen.com/english/advisories/2010/0528http://www.vupen.com/english/advisories/2010/0622https://bugzilla.redhat.com/show_bug.cgi?id=538744https://exchange.xforce.ibmcloud.com/vulnerabilities/54416https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://issues.rpath.com/browse/RPL-3152https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10821https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11745https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7261https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7459https://www.isc.org/advisories/CVE-2009-4022v6https://www.isc.org/advisories/CVE2009-4022https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01172.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg01188.html
2009-11-25
Published