CVE-2010-0218
published 2010-10-05CVE-2010-0218: ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.50%
88.4th percentile
ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p54f-fcg2-57wc: ISC BIND 9
ghsa_unreviewed·2022-05-02
CVE-2010-0218 [MEDIUM] GHSA-p54f-fcg2-57wc: ISC BIND 9
ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.
Red Hat
Bind: Unitended availability of cache data.
vendor_redhat·2010-09-28·CVSS 5.0
CVE-2010-0218 [MEDIUM] Bind: Unitended availability of cache data.
Bind: Unitended availability of cache data.
ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.
Statement: Not vulnerable. This issue did not affect the versions of bind package as
shipped with Red Hat Enterprise Linux 3, 4, or 5.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-0218: bind9 - ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of...
vendor_debian·2010·CVSS 5.0
CVE-2010-0218 [MEDIUM] CVE-2010-0218: bind9 - ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of...
ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.htmlhttp://www.kb.cert.org/vuls/id/784855https://lists.isc.org/pipermail/bind-announce/2010-September/000655.htmlhttp://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.htmlhttp://www.kb.cert.org/vuls/id/784855https://lists.isc.org/pipermail/bind-announce/2010-September/000655.html
2010-10-05
Published