CVE-2009-0696

Description

The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
33.301

Associated Vulnerability

VulnerabilityOS Platform
Update bind 9.6.1 to latest versionWindows
Multiple Vulnerabilities are affected in BIND 9.4.0Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.rc1Windows
Multiple Vulnerabilities are affected in BIND 9.5.0Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.a1Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.a2Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.a3Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.a4Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.a5Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.b1Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.b2Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.b3Windows
Multiple Vulnerabilities are affected in BIND 9.5.0.a1Windows
Multiple Vulnerabilities are affected in BIND 9.4.1Windows
Multiple Vulnerabilities are affected in BIND 9.4Windows
Multiple Vulnerabilities are affected in BIND 9.5Windows
Multiple Vulnerabilities are affected in BIND 9.4.2Windows
Multiple Vulnerabilities are affected in BIND 9.5.0.p2_w1Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.a6Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.b4Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.rc2Windows
Multiple Vulnerabilities are affected in BIND 9.4.2.rc1Windows
Multiple Vulnerabilities are affected in BIND 9.4.2.rc2Windows
Multiple Vulnerabilities are affected in BIND 9.4.3Windows
Multiple Vulnerabilities are affected in BIND 9.4.3.b1Windows
Multiple Vulnerabilities are affected in BIND 9.4.3.b2Windows
Multiple Vulnerabilities are affected in BIND 9.4.3.b3Windows
Multiple Vulnerabilities are affected in BIND 9.6.0Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.4.3.p2Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.a2Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.a3Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.a4Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.a5Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.a6Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.a7Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.b1Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.b2Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.b3Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.p1Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.p2Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.5.0.p2_w2Windows
Multiple Vulnerabilities are affected in BIND 9.6Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.0.a1Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.0.b1Windows
Multiple Vulnerabilities are affected in BIND 9.6.0.p1Windows
Multiple Vulnerabilities are affected in BIND 9.6.0.rc1Windows
Multiple Vulnerabilities are affected in BIND 9.6.0.rc2Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.1Windows
Vulnerabilities CVE-2009-0696,CVE-2009-4022,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.1.b1Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2010-3613,CVE-2011-1910 are affected in BIND 9.6.r1Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2010-3613,CVE-2011-1910 are affected in BIND 9.6.r2Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r3Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r4Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r4_p1Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r5Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r5_b1Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r5_p1Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r6Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r6_b1Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r6_rc1Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r6_rc2Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r7Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r7_p1Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r7_p2Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r9Windows
Vulnerabilities CVE-2009-0696,CVE-2010-0097,CVE-2011-1910 are affected in BIND 9.6.r9_p1Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234