cbcvebase.

Debian Bind9 vulnerabilities

166 known vulnerabilities affecting debian/bind9.

Total CVEs
166
CISA KEV
0
Public exploits
9
Exploited in wild
2
Severity breakdown
HIGH73MEDIUM35LOW58

Vulnerabilities

Page 7 of 9
CVE-2012-1667HIGHCVSS 8.5fixed in bind9 1:9.8.1.dfsg.P1-4.1 (bookworm)2012
CVE-2012-1667 [HIGH] CVE-2012-1667: bind9 - ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and ... ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record. Scope:
debian
CVE-2012-3817HIGHCVSS 7.8fixed in bind9 1:9.8.1.dfsg.P1-4.2 (bookworm)2012
CVE-2012-3817 [HIGH] CVE-2012-3817: bind9 - ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; ... ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries. Scope: local bookworm: res
debian
CVE-2012-5166HIGHCVSS 7.8fixed in bind9 1:9.8.1.dfsg.P1-4.3 (bookworm)2012
CVE-2012-5166 [HIGH] CVE-2012-5166: bind9 - ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and ... ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records. Scope: local bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-4.3) bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-4.3) forky: resolved
debian
CVE-2012-5688HIGHCVSS 7.8fixed in bind9 1:9.8.4.dfsg.P1-1 (bookworm)2012
CVE-2012-5688 [HIGH] CVE-2012-5688: bind9 - ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled,... ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query. Scope: local bookworm: resolved (fixed in 1:9.8.4.dfsg.P1-1) bullseye: resolved (fixed in 1:9.8.4.dfsg.P1-1) forky: resolved (fixed in 1:9.8.4.dfsg.P1-1) sid: resolved (fixed in 1:9
debian
CVE-2012-5689HIGHCVSS 7.1fixed in bind9 1:9.8.4.dfsg.P1-6+nmu1 (bookworm)2012
CVE-2012-5689 [HIGH] CVE-2012-5689: bind9 - ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configura... ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record. Scope: local bookworm: resolved (fixed in 1:9.8.4.dfsg.P1-6+nmu1) bullseye: resolv
debian
CVE-2012-3868LOWCVSS 4.32012
CVE-2012-3868 [MEDIUM] CVE-2012-3868: bind9 - Race condition in the ns_client structure management in ISC BIND 9.9.x before 9.... Race condition in the ns_client structure management in ISC BIND 9.9.x before 9.9.1-P2 allows remote attackers to cause a denial of service (memory consumption or process exit) via a large volume of TCP queries. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2012-1033LOWCVSS 5.0fixed in bind9 1:9.8.1.dfsg.P1-4.1 (bookworm)2012
CVE-2012-1033 [MEDIUM] CVE-2012-1033: bind9 - The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and T... The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack. Scope: local bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-4.1) bullseye: resolved (f
debian
CVE-2011-0414HIGHCVSS 7.1fixed in bind9 1:9.7.3.dfsg-1 (bookworm)2011
CVE-2011-0414 [HIGH] CVE-2011-0414: bind9 - ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, all... ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update. Scope: local bookworm: resolved (fixed in 1:9.7.3.dfsg-1) bullseye: resolved (fixed in 1:9.7.3.dfsg-1) forky: resolved (fixed in 1:9.7.3.d
debian
CVE-2011-2464HIGHCVSS 5.0fixed in bind9 1:9.8.1.dfsg-1 (bookworm)2011
CVE-2011-2464 [MEDIUM] CVE-2011-2464: bind9 - Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before... Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request. Scope: local bookworm: resolved (fixed in 1:9.8.1.dfsg-1) bullseye: resolved (fixed in 1:9.8.1.dfsg-1) forky: resolved (fixed in 1:9.8.1.dfsg-1) sid:
debian
CVE-2011-4313HIGHCVSS 5.0fixed in bind9 1:9.8.1.dfsg.P1-1 (bookworm)2011
CVE-2011-4313 [MEDIUM] CVE-2011-4313: bind9 - query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV thr... query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the re
debian
CVE-2011-1910HIGHCVSS 5.0fixed in bind9 1:9.8.1.dfsg-1 (bookworm)2011
CVE-2011-1910 [MEDIUM] CVE-2011-1910: bind9 - Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2... Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets. Scope: local bookworm: resolved (fixed in 1:9.8.1.dfsg-1) bullseye: resolved (f
debian
CVE-2011-1907MEDIUMCVSS 5.0fixed in bind9 1:9.8.1.dfsg.P1-1 (bookworm)2011
CVE-2011-1907 [MEDIUM] CVE-2011-1907: bind9 - ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replaceme... ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG query. Scope: local bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-1) bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-1) forky: resolved (fixed in 1:9.8.1.dfsg.P1-1) sid: resolve
debian
CVE-2011-2465LOWCVSS 2.6fixed in bind9 1:9.8.1.dfsg.P1-1 (bookworm)2011
CVE-2011-2465 [LOW] CVE-2011-2465: bind9 - Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, ... Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query. Scope: local bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-1) bullseye: resolved (fixed in 1
debian
CVE-2010-3762MEDIUMCVSS 4.3fixed in bind9 1:9.7.2.dfsg.P2-1 (bookworm)2010
CVE-2010-3762 [MEDIUM] CVE-2010-3762: bind9 - ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly h... ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query. Scope: local bookworm: resolved (fixed in 1:9.7.2.dfsg.P2-1) bullseye: resolved (fixed in 1:9.7.2.dfsg.P2-1) forky: res
debian
CVE-2010-3614MEDIUMCVSS 6.4fixed in bind9 1:9.7.2.dfsg.P3-1 (bookworm)2010
CVE-2010-3614 [MEDIUM] CVE-2010-3614: bind9 - named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4... named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover. Scope: local bookworm: resolved (fix
debian
CVE-2010-3613MEDIUMCVSS 4.0fixed in bind9 1:9.7.2.dfsg.P3-1 (bookworm)2010
CVE-2010-3613 [MEDIUM] CVE-2010-3613: bind9 - named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x be... named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data. Scope: local bookworm: resolved (fixed in 1:9.7.2.dfsg.P3
debian
CVE-2010-0097MEDIUMCVSS 4.3fixed in bind9 1:9.7.0.dfsg-1 (bookworm)2010
CVE-2010-0097 [MEDIUM] CVE-2010-0097: bind9 - ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 befo... ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain. Scope: local bookworm: resolved (fixed in 1:9.7.0.dfsg-1) bullseye: reso
debian
CVE-2010-3615MEDIUMCVSS 5.0fixed in bind9 1:9.7.2.dfsg.P3-1 (bookworm)2010
CVE-2010-3615 [MEDIUM] CVE-2010-3615: bind9 - named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query... named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism. Scope: local bookworm: resolved (fixed in 1:9.7.2.dfsg.P3-1) bullseye: resolved (fixed in 1:9.7.2.dfsg.P3-1) forky: resolved (fixed in 1:9.7.2.dfsg.P3-1) sid:
debian
CVE-2010-0290MEDIUMCVSS 2.6fixed in bind9 1:9.7.0.dfsg-1 (bookworm)2010
CVE-2010-0290 [LOW] CVE-2010-0290: bind9 - Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, ... Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which
debian
CVE-2010-0382LOWCVSS 2.6fixed in bind9 1:9.7.0.dfsg-1 (bookworm)2010
CVE-2010-0382 [LOW] CVE-2010-0382: bind9 - ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 befo... ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression dur
debian