CVE-2010-3762
published 2010-10-05CVE-2010-3762: ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
8.09%
94.2th percentile
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.7.2.dfsg.P2-1 (bookworm) | bind9 1:9.7.2.dfsg.P2-1 (bookworm) |
| isc | bind | <= 9.7.2 | — |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P2-1 | 1:9.7.2.dfsg.P2-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P2-1 | 1:9.7.2.dfsg.P2-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P2-1 | 1:9.7.2.dfsg.P2-1 |
| isc | bind9 | >= 0 < 1:9.7.2.dfsg.P2-1 | 1:9.7.2.dfsg.P2-1 |
| vmware | vmware_esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2011-05-30·CVSS 4.3
CVE-2010-3762 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: An attacker could send crafted input to Bind and cause it to crash.
It was discovered that Bind incorrectly handled certain bad signatures if
multiple trust anchors existed for a single zone. A remote attacker could
use this flaw to cause Bind to stop responding, resulting in a denial of
service. This issue only affected Ubuntu 8.04 LTS and 10.04 LTS.
(CVE-2010-3762)
Frank Kloeker and Michael Sinatra discovered that Bind incorrectly handled
certain very large RRSIG RRsets included in negative responses. A remote
attacker could use this flaw to cause Bind to stop responding, resulting in
a denial of service. (CVE-2011-1910)
Instructions: In general, a standard system update will make all the necessary changes.
VMware
VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
vendor_vmware·2011-03-07·CVSS 5.0
CVE-2010-2059 [MEDIUM] VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
VMSA-2011-0004: VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
a. Service Location Protocol daemon DoS This patch fixes a denial-of-service vulnerability in the Service Location Protocol daemon (SLPD). Exploitation of this vulnerability could cause SLPD to consume significant CPU resources. VMware would like to thank Nicolas Gregoire and US CERT for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-3609 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/
Red Hat
Bind: DoS (assertion failure) via a DNS query with bad signatures
vendor_redhat·2010-09-28·CVSS 4.3
CVE-2010-3762 [MEDIUM] Bind: DoS (assertion failure) via a DNS query with bad signatures
Bind: DoS (assertion failure) via a DNS query with bad signatures
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-3762: bind9 - ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly h...
vendor_debian·2010·CVSS 4.3
CVE-2010-3762 [MEDIUM] CVE-2010-3762: bind9 - ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly h...
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
Scope: local
bookworm: resolved (fixed in 1:9.7.2.dfsg.P2-1)
bullseye: resolved (fixed in 1:9.7.2.dfsg.P2-1)
forky: resolved (fixed in 1:9.7.2.dfsg.P2-1)
sid: resolved (fixed in 1:9.7.2.dfsg.P2-1)
trixie: resolved (fixed in 1:9.7.2.dfsg.P2-1)
GHSA
GHSA-hv8v-8gq8-6q29: ISC BIND before 9
ghsa_unreviewed·2022-05-14
CVE-2010-3762 [MEDIUM] CWE-20 GHSA-hv8v-8gq8-6q29: ISC BIND before 9
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
OSV
CVE-2010-3762: ISC BIND before 9
osv·2010-10-05·CVSS 4.3
CVE-2010-3762 [MEDIUM] CVE-2010-3762: ISC BIND before 9
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
No detection rules found.
No public exploits indexed.
http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://support.avaya.com/css/P8/documents/100124923http://www.debian.org/security/2010/dsa-2130http://www.mandriva.com/security/advisories?name=MDVSA-2010:253http://www.redhat.com/support/errata/RHSA-2010-0976.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.securityfocus.com/bid/45385http://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://support.avaya.com/css/P8/documents/100124923http://www.debian.org/security/2010/dsa-2130http://www.mandriva.com/security/advisories?name=MDVSA-2010:253http://www.redhat.com/support/errata/RHSA-2010-0976.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.securityfocus.com/bid/45385http://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606
2010-10-05
Published