CVE-2010-3614
published 2010-12-06CVE-2010-3614: named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security…
PriorityP333medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
14.50%
96.3th percentile
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.7.2.dfsg.P3-1 (bookworm) | bind9 1:9.7.2.dfsg.P3-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
vendor_vmware·2011-03-07·CVSS 5.0
CVE-2010-2059 [MEDIUM] VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
VMSA-2011-0004: VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
a. Service Location Protocol daemon DoS This patch fixes a denial-of-service vulnerability in the Service Location Protocol daemon (SLPD). Exploitation of this vulnerability could cause SLPD to consume significant CPU resources. VMware would like to thank Nicolas Gregoire and US CERT for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-3609 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2010-12-01·CVSS 4.0
CVE-2010-3613 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
It was discovered that Bind would incorrectly allow a ncache entry and a
rrsig for the same type. A remote attacker could exploit this to cause
Bind to crash, resulting in a denial of service. (CVE-2010-3613)
It was discovered that Bind would incorrectly mark zone data as insecure
when the zone is undergoing a key algorithm rollover. (CVE-2010-3614)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: key algorithm rollover may mark secure answers as insecure
vendor_redhat·2010-12-01·CVSS 6.4
CVE-2010-3614 [MEDIUM] bind: key algorithm rollover may mark secure answers as insecure
bind: key algorithm rollover may mark secure answers as insecure
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. Because the version of bind in Red Hat Enterprise Linux 4 does not implement support for the currently-used DNSSEC protocol version, there is no plan to address this flaw there. It has been addressed in Red Hat Enterprise Linux 5 (via RHSA-2010:0975) and Red Hat Enterprise Linux 6 (via RHSA-2010:0976
Debian
CVE-2010-3614: bind9 - named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4...
vendor_debian·2010·CVSS 6.4
CVE-2010-3614 [MEDIUM] CVE-2010-3614: bind9 - named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4...
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
Scope: local
bookworm: resolved (fixed in 1:9.7.2.dfsg.P3-1)
bullseye: resolved (fixed in 1:9.7.2.dfsg.P3-1)
forky: resolved (fixed in 1:9.7.2.dfsg.P3-1)
sid: resolved (fixed in 1:9.7.2.dfsg.P3-1)
trixie: resolved (fixed in 1:9.7.2.dfsg.P3-1)
GHSA
GHSA-r6jr-r827-mr54: named in ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2010-3614 [MEDIUM] CWE-20 GHSA-r6jr-r827-mr54: named in ISC BIND 9
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
OSV
CVE-2010-3614: named in ISC BIND 9
osv·2010-12-06·CVSS 6.4
CVE-2010-3614 [MEDIUM] CVE-2010-3614: named in ISC BIND 9
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
No detection rules found.
Bugzilla
CVE-2010-3613 bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
bugzilla·2010-12-01·CVSS 4.0
CVE-2010-3613 [MEDIUM] CVE-2010-3613 bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
CVE-2010-3613 bind: failure to clear existing RRSIG records when a NO DATA is negatively cached could DoS named
A flaw in how BIND fails to clear existing RRSIG records when a NO DATA is negatively cached could cause subsequent lookups to crash named (INSIST) was reported [1].
The advisory states:
"Although the defect is very unlikely to be encountered in normal operation, if your recursive resolver is being used to query public Internet zones and you cannot readily restrict your client queries then there is the potential for a remote attacker to cause your nameserver to crash."
The INSIST crashes the server. This vulnerability affects recursive nameservers irrespective of whether DNSSEC validation is enabled or disabled.
The upstream advisory [2] notes that this affects BIND versions
Bugzilla
CVE-2010-3614 bind: key algorithm rollover may mark secure answers as insecure
bugzilla·2010-12-01·CVSS 6.4
CVE-2010-3614 [MEDIUM] CVE-2010-3614 bind: key algorithm rollover may mark secure answers as insecure
CVE-2010-3614 bind: key algorithm rollover may mark secure answers as insecure
A flaw was found in how named (acting as a DNSSEC validating resolver) could incorrectly mark zone data as insecure when the zone being queried is undergoing a key algorithm rollover [1].
The advisory states:
"named, acting as a DNSSEC validator, was determining if an NS RRset is insecure based on a value that could mean either that the RRset is actually insecure or that there wasn't a matching key for the RRSIG in the DNSKEY RRset when resuming from validating the DNSKEY RRset. This can happen when in the middle of a DNSKEY algorithm rollover, when two different algorithms were used to sign a zone but only the new set of keys are in the zone DNSKEY RRset."
The upstream advisory [2] notes that this affects a
Bugzilla
CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
bugzilla·2010-12-01·CVSS 4.0
CVE-2010-3615 [MEDIUM] CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
fedora-14 tracking bug for bind: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-3613
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=658982,658974
---
Adding parent bug CVE-2010-3614
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=658982,658974,658977
---
bind-9.7.2-4.P3.fc14 has been submitted as an update for Fedora 14.
https://admin.fedoraproject.org/updates/bind-9.7.2-4.P3.fc14
---
bind-9.7.2-4.P3.fc14 has been pushed to the Fed
Bugzilla
CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-13]
bugzilla·2010-12-01·CVSS 4.0
CVE-2010-3613 [MEDIUM] CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-13]
CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-13]
fedora-13 tracking bug for bind: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-3614
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=658974,658977
---
bind-9.7.2-1.P3.fc13,bind-dyndb-ldap-0.1.0-0.10.a1.20091210git.fc13,dnsperf-1.0.1.0-19.fc13 has been submitted as an update for Fedora 13.
https://admin.fedoraproject.org/updates/bind-9.7.2-1.P3.fc13,bind-dyndb-ldap-0.1.0-0.10.a1.20091210git.fc13,dnsperf-1.0.1.0-19.fc13
---
bind-9.7.2-1.P3.fc13, bind-dyndb-ldap-0.1.0-0.10.a1.20091210git.f
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051910.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051963.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://secunia.com/advisories/42435http://secunia.com/advisories/42459http://secunia.com/advisories/42522http://secunia.com/advisories/42671http://securitytracker.com/id?1024817http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.622190http://support.apple.com/kb/HT5002http://support.avaya.com/css/P8/documents/100124923http://www.debian.org/security/2010/dsa-2130http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisorieshttp://www.isc.org/software/bind/advisories/cve-2010-3614http://www.kb.cert.org/vuls/id/837744http://www.mandriva.com/security/advisories?name=MDVSA-2010:253http://www.osvdb.org/69559http://www.redhat.com/support/errata/RHSA-2010-0975.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0976.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.securityfocus.com/bid/45137http://www.ubuntu.com/usn/USN-1025-1http://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2010/3102http://www.vupen.com/english/advisories/2010/3103http://www.vupen.com/english/advisories/2010/3138http://www.vupen.com/english/advisories/2010/3139http://www.vupen.com/english/advisories/2010/3140http://www.vupen.com/english/advisories/2011/0606http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051910.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051963.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://secunia.com/advisories/42435http://secunia.com/advisories/42459http://secunia.com/advisories/42522http://secunia.com/advisories/42671http://securitytracker.com/id?1024817http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.622190http://support.apple.com/kb/HT5002http://support.avaya.com/css/P8/documents/100124923http://www.debian.org/security/2010/dsa-2130http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisorieshttp://www.isc.org/software/bind/advisories/cve-2010-3614http://www.kb.cert.org/vuls/id/837744http://www.mandriva.com/security/advisories?name=MDVSA-2010:253http://www.osvdb.org/69559http://www.redhat.com/support/errata/RHSA-2010-0975.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0976.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.securityfocus.com/bid/45137http://www.ubuntu.com/usn/USN-1025-1http://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2010/3102http://www.vupen.com/english/advisories/2010/3103http://www.vupen.com/english/advisories/2010/3138http://www.vupen.com/english/advisories/2010/3139http://www.vupen.com/english/advisories/2010/3140http://www.vupen.com/english/advisories/2011/0606
2010-12-06
Published