Description
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
CVSS vector
AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9Complexity: Low
Confidentiality: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-r6jr-r827-mr54: named in ISC BIND 9↗2022-05-14 ▶ OSVCVE-2010-3614: named in ISC BIND 9↗2010-12-06 ▶ CVEListCVE-2010-3614: named in ISC BIND 9↗2010-12-03 ▶ 💥Exploits & PoCs
1Exploit-DBSAP DB 7.4 - WebTools Buffer Overflow (Metasploit)↗2010-07-16 ▶ 📋Vendor Advisories
3UbuntuBind vulnerabilities↗2010-12-01 ▶ Red Hatbind: key algorithm rollover may mark secure answers as insecure↗2010-12-01 ▶ DebianCVE-2010-3614: bind9 - named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4...↗2010 ▶ 💬Community
3BugzillaCVE-2010-3614 bind: key algorithm rollover may mark secure answers as insecure↗2010-12-01 ▶ BugzillaCVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]↗2010-12-01 ▶ BugzillaCVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-13]↗2010-12-01 ▶