CVE-2010-3613
published 2010-12-06CVE-2010-3613: named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative…
PriorityP423medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
9.10%
94.8th percentile
named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.7.2.dfsg.P3-1 (bookworm) | bind9 1:9.7.2.dfsg.P3-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P3-1 | 1:9.7.2.dfsg.P3-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P3-1 | 1:9.7.2.dfsg.P3-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P3-1 | 1:9.7.2.dfsg.P3-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P3-1 | 1:9.7.2.dfsg.P3-1 |
| vmware | vmware_esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
vendor_vmware·2011-03-07·CVSS 5.0
CVE-2010-2059 [MEDIUM] VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
VMSA-2011-0004: VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
a. Service Location Protocol daemon DoS This patch fixes a denial-of-service vulnerability in the Service Location Protocol daemon (SLPD). Exploitation of this vulnerability could cause SLPD to consume significant CPU resources. VMware would like to thank Nicolas Gregoire and US CERT for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-3609 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/
Red Hat
bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
vendor_redhat·2010-12-01·CVSS 4.0
CVE-2010-3613 [MEDIUM] bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.
Package: bind97 (Red Hat Enterprise Linux 5) - Affected
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2010-12-01·CVSS 4.0
CVE-2010-3613 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
It was discovered that Bind would incorrectly allow a ncache entry and a
rrsig for the same type. A remote attacker could exploit this to cause
Bind to crash, resulting in a denial of service. (CVE-2010-3613)
It was discovered that Bind would incorrectly mark zone data as insecure
when the zone is undergoing a key algorithm rollover. (CVE-2010-3614)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2010-3613: bind9 - named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x be...
vendor_debian·2010·CVSS 4.0
CVE-2010-3613 [MEDIUM] CVE-2010-3613: bind9 - named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x be...
named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.
Scope: local
bookworm: resolved (fixed in 1:9.7.2.dfsg.P3-1)
bullseye: resolved (fixed in 1:9.7.2.dfsg.P3-1)
forky: resolved (fixed in 1:9.7.2.dfsg.P3-1)
sid: resolved (fixed in 1:9.7.2.dfsg.P3-1)
trixie: resolved (fixed in 1:9.7.2.dfsg.P3-1)
GHSA
GHSA-7hh4-vqqp-5g89: named in ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2010-3613 [MEDIUM] GHSA-7hh4-vqqp-5g89: named in ISC BIND 9
named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.
OSV
CVE-2010-3613: named in ISC BIND 9
osv·2010-12-06·CVSS 4.0
CVE-2010-3613 [MEDIUM] CVE-2010-3613: named in ISC BIND 9
named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3613 bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
bugzilla·2010-12-01·CVSS 4.0
CVE-2010-3613 [MEDIUM] CVE-2010-3613 bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
CVE-2010-3613 bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
A flaw in how BIND fails to clear existing RRSIG records when a NO DATA is negatively cached could cause subsequent lookups to crash named (INSIST) was reported [1].
The advisory states:
"Although the defect is very unlikely to be encountered in normal operation, if your recursive resolver is being used to query public Internet zones and you cannot readily restrict your client queries then there is the potential for a remote attacker to cause your nameserver to crash."
The INSIST crashes the server. This vulnerability affects recursive nameservers irrespective of whether DNSSEC validation is enabled or disabled.
The upstream advisory [2] notes that this affects BIND versions
Bugzilla
CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
bugzilla·2010-12-01·CVSS 4.0
CVE-2010-3615 [MEDIUM] CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
fedora-14 tracking bug for bind: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-3613
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=658982,658974
---
Adding parent bug CVE-2010-3614
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=658982,658974,658977
---
bind-9.7.2-4.P3.fc14 has been submitted as an update for Fedora 14.
https://admin.fedoraproject.org/updates/bind-9.7.2-4.P3.fc14
---
bind-9.7.2-4.P3.fc14 has been pushed to the Fed
Bugzilla
CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-13]
bugzilla·2010-12-01·CVSS 4.0
CVE-2010-3613 [MEDIUM] CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-13]
CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-13]
fedora-13 tracking bug for bind: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-3614
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=658974,658977
---
bind-9.7.2-1.P3.fc13,bind-dyndb-ldap-0.1.0-0.10.a1.20091210git.fc13,dnsperf-1.0.1.0-19.fc13 has been submitted as an update for Fedora 13.
https://admin.fedoraproject.org/updates/bind-9.7.2-1.P3.fc13,bind-dyndb-ldap-0.1.0-0.10.a1.20091210git.fc13,dnsperf-1.0.1.0-19.fc13
---
bind-9.7.2-1.P3.fc13, bind-dyndb-ldap-0.1.0-0.10.a1.20091210git.f
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-001.txt.aschttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051910.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051963.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://marc.info/?l=bugtraq&m=130270720601677&w=2http://secunia.com/advisories/42374http://secunia.com/advisories/42459http://secunia.com/advisories/42522http://secunia.com/advisories/42671http://secunia.com/advisories/42707http://secunia.com/advisories/43141http://securitytracker.com/id?1024817http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.622190http://support.apple.com/kb/HT5002http://support.avaya.com/css/P8/documents/100124923http://www.debian.org/security/2010/dsa-2130http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisorieshttp://www.isc.org/software/bind/advisories/cve-2010-3613http://www.kb.cert.org/vuls/id/706148http://www.mandriva.com/security/advisories?name=MDVSA-2010:253http://www.osvdb.org/69558http://www.redhat.com/support/errata/RHSA-2010-0975.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0976.htmlhttp://www.redhat.com/support/errata/RHSA-2010-1000.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.securityfocus.com/bid/45133http://www.ubuntu.com/usn/USN-1025-1http://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2010/3102http://www.vupen.com/english/advisories/2010/3103http://www.vupen.com/english/advisories/2010/3138http://www.vupen.com/english/advisories/2010/3139http://www.vupen.com/english/advisories/2010/3140http://www.vupen.com/english/advisories/2011/0267http://www.vupen.com/english/advisories/2011/0606https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12601http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-001.txt.aschttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051910.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051963.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://marc.info/?l=bugtraq&m=130270720601677&w=2http://secunia.com/advisories/42374http://secunia.com/advisories/42459http://secunia.com/advisories/42522http://secunia.com/advisories/42671http://secunia.com/advisories/42707http://secunia.com/advisories/43141http://securitytracker.com/id?1024817http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.622190http://support.apple.com/kb/HT5002http://support.avaya.com/css/P8/documents/100124923http://www.debian.org/security/2010/dsa-2130http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisorieshttp://www.isc.org/software/bind/advisories/cve-2010-3613http://www.kb.cert.org/vuls/id/706148http://www.mandriva.com/security/advisories?name=MDVSA-2010:253http://www.osvdb.org/69558http://www.redhat.com/support/errata/RHSA-2010-0975.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0976.htmlhttp://www.redhat.com/support/errata/RHSA-2010-1000.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.securityfocus.com/bid/45133http://www.ubuntu.com/usn/USN-1025-1http://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2010/3102http://www.vupen.com/english/advisories/2010/3103http://www.vupen.com/english/advisories/2010/3138http://www.vupen.com/english/advisories/2010/3139http://www.vupen.com/english/advisories/2010/3140http://www.vupen.com/english/advisories/2011/0267http://www.vupen.com/english/advisories/2011/0606https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12601
2010-12-06
Published