CVE-2010-3613

Modified
Published: 03 Dec 2010, 20:00
Last modified:07 Aug 2024, 03:18

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
3.21% LOW
3% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Dec 2010, 20:00
Published
Vulnerability first disclosed
07 Aug 2024, 03:18
Last Modified
Vulnerability information updated

Description

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in the cache, which allows remote attackers to cause a denial of service (daemon crash) via a query for cached data.

CVSS Metrics

  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 3.21% Percentile: 87%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • iscbind

    9.6 | 9.6:r1 | 9.6:r2 | 9.6.2 | 9.6.2:b1 | 9.6.2:p1 | 9.6.2:p2 | 9.7.0 | 9.7.0:a1 | 9.7.0:a2 | 9.7.0:a3 | 9.7.0:b1 | 9.7.0:b2 | 9.7.0:b3 | 9.7.0:p1 | 9.7.0:p2 | 9.7.0:rc1 | 9.7.0:rc2 | 9.7.1 | 9.7.1:b1 | 9.7.1:p1 | 9.7.1:p2 | 9.7.1:rc1 | 9.7.2 | 9.7.2:p1 | 9.7.2:p2

References (37)