CVE-2010-0218Bind vulnerability

CWE-2646 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
2.1%
top 15.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 5
Latest updateMay 2

Description

ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDisc/bind9.7.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p54f-fcg2-57wc: ISC BIND 92022-05-02
CVEList
CVE-2010-0218: ISC BIND 92010-10-05

📋Vendor Advisories

2
Red Hat
Bind: Unitended availability of cache data.2010-09-28
Debian
CVE-2010-0218: bind9 - ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of...2010

💬Community

1
Bugzilla
CVE-2010-0218 Bind: Unitended availability of cache data.2010-10-06
CVE-2010-0218 — ISC Bind vulnerability | cvebase