CVE-2010-3615
published 2010-12-06CVE-2010-3615: named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
9.79%
95.0th percentile
named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.7.2.dfsg.P3-1 (bookworm) | bind9 1:9.7.2.dfsg.P3-1 (bookworm) |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P3-1 | 1:9.7.2.dfsg.P3-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P3-1 | 1:9.7.2.dfsg.P3-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P3-1 | 1:9.7.2.dfsg.P3-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P3-1 | 1:9.7.2.dfsg.P3-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j2v8-rqc3-xfr2: named in ISC BIND 9
ghsa_unreviewed·2022-05-17
CVE-2010-3615 [MEDIUM] GHSA-j2v8-rqc3-xfr2: named in ISC BIND 9
named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
OSV
CVE-2010-3615: named in ISC BIND 9
osv·2010-12-06·CVSS 5.0
CVE-2010-3615 [MEDIUM] CVE-2010-3615: named in ISC BIND 9
named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
Red Hat
bind: allow-query processed incorrectly allowing access to authoritative zones that should be restricted
vendor_redhat·2010-12-01·CVSS 5.0
CVE-2010-3615 [MEDIUM] bind: allow-query processed incorrectly allowing access to authoritative zones that should be restricted
bind: allow-query processed incorrectly allowing access to authoritative zones that should be restricted
named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
Statement: Not vulnerable. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Debian
CVE-2010-3615: bind9 - named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query...
vendor_debian·2010·CVSS 5.0
CVE-2010-3615 [MEDIUM] CVE-2010-3615: bind9 - named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query...
named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
Scope: local
bookworm: resolved (fixed in 1:9.7.2.dfsg.P3-1)
bullseye: resolved (fixed in 1:9.7.2.dfsg.P3-1)
forky: resolved (fixed in 1:9.7.2.dfsg.P3-1)
sid: resolved (fixed in 1:9.7.2.dfsg.P3-1)
trixie: resolved (fixed in 1:9.7.2.dfsg.P3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3615 bind: allow-query processed incorrectly allowing access to authoritative zones that should be restricted
bugzilla·2010-12-01·CVSS 5.0
CVE-2010-3615 [MEDIUM] CVE-2010-3615 bind: allow-query processed incorrectly allowing access to authoritative zones that should be restricted
CVE-2010-3615 bind: allow-query processed incorrectly allowing access to authoritative zones that should be restricted
A flaw was found in BIND where the "allow-query" in the "options" or "view" statements to restrict access to authoritative zones had no effect [1].
The advisory states:
"When named is running as an authoritative server for a zone and receives a query for that zone data, it first checks for allow-query acls in the zone statement, then in that view, then in global options. If none of these exist, it defaults to allowing any query (allow-query {"any"};).
With this bug, if the allow-query is not set in the zone statement, it failed to check in view or global options and fell back to the default of allowing any query. This means that queries that the zone owner did not wish
Bugzilla
CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
bugzilla·2010-12-01·CVSS 4.0
CVE-2010-3615 [MEDIUM] CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
CVE-2010-3615 CVE-2010-3613 CVE-2010-3614 bind various flaws [fedora-14]
fedora-14 tracking bug for bind: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-3613
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=658982,658974
---
Adding parent bug CVE-2010-3614
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=658982,658974,658977
---
bind-9.7.2-4.P3.fc14 has been submitted as an update for Fedora 14.
https://admin.fedoraproject.org/updates/bind-9.7.2-4.P3.fc14
---
bind-9.7.2-4.P3.fc14 has been pushed to the Fed
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051963.htmlhttp://osvdb.org/69568http://secunia.com/advisories/42458http://secunia.com/advisories/42671http://securitytracker.com/id?1024817http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.622190http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisorieshttp://www.isc.org/software/bind/advisories/cve-2010-3615http://www.kb.cert.org/vuls/id/510208http://www.securityfocus.com/bid/45134http://www.vupen.com/english/advisories/2010/3102http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051963.htmlhttp://osvdb.org/69568http://secunia.com/advisories/42458http://secunia.com/advisories/42671http://securitytracker.com/id?1024817http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.622190http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisorieshttp://www.isc.org/software/bind/advisories/cve-2010-3615http://www.kb.cert.org/vuls/id/510208http://www.securityfocus.com/bid/45134http://www.vupen.com/english/advisories/2010/3102
2010-12-06
Published