CVE-2012-1033

Description

The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a ghost domain names attack.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
1.868

Associated Vulnerability

VulnerabilityOS Platform
Update bind 9.8.1 to latest versionWindows
Multiple Vulnerabilities are affected in BIND 9.4.0Windows
Multiple Vulnerabilities are affected in BIND 9.1.2Windows
Multiple Vulnerabilities are affected in BIND 9.0Windows
Multiple Vulnerabilities are affected in BIND 9.1Windows
Multiple Vulnerabilities are affected in BIND 9.1.1Windows
Multiple Vulnerabilities are affected in BIND 9.1.3Windows
Multiple Vulnerabilities are affected in BIND 9.2Windows
Multiple Vulnerabilities are affected in BIND 9.3.0Windows
Multiple Vulnerabilities are affected in BIND 9.3.2Windows
Multiple Vulnerabilities are affected in BIND 9.0.1Windows
Multiple Vulnerabilities are affected in BIND 9.2.0Windows
Multiple Vulnerabilities are affected in BIND 9.2.1Windows
Multiple Vulnerabilities are affected in BIND 9.2.2Windows
Multiple Vulnerabilities are affected in BIND 9.2.3Windows
Multiple Vulnerabilities are affected in BIND 9.3Windows
Multiple Vulnerabilities are affected in BIND 9.3.1Windows
Multiple Vulnerabilities are affected in BIND 9.2.6Windows
Multiple Vulnerabilities are affected in BIND 9.2.4Windows
Multiple Vulnerabilities are affected in BIND 9.2.5Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.rc1Windows
Multiple Vulnerabilities are affected in BIND 9.5.0Windows
Multiple Vulnerabilities are affected in BIND 9.2.2.p3Windows
Multiple Vulnerabilities are affected in BIND 9.4.1Windows
Multiple Vulnerabilities are affected in BIND 9.4Windows
Multiple Vulnerabilities are affected in BIND 9.5Windows
Multiple Vulnerabilities are affected in BIND 9.4.2Windows
Multiple Vulnerabilities are affected in BIND 9.2.7Windows
Multiple Vulnerabilities are affected in BIND 9.4.3Windows
Multiple Vulnerabilities are affected in BIND 9.4.3.rc1Windows
Multiple Vulnerabilities are affected in BIND 9.5.1Windows
Multiple Vulnerabilities are affected in BIND 9.6.0Windows
Multiple Vulnerabilities are affected in BIND 9.6.0.p1Windows
Multiple Vulnerabilities are affected in BIND 9.6.0.rc1Windows
Multiple Vulnerabilities are affected in BIND 9.6.0.rc2Windows
Vulnerabilities CVE-2009-4022,CVE-2010-0097,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.3.3Windows
Vulnerabilities CVE-2009-4022,CVE-2010-0097,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.5.0.rc1Windows
Vulnerabilities CVE-2009-4022,CVE-2010-0097,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.5.1.rc1Windows
Vulnerabilities CVE-2009-4022,CVE-2010-0097,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.5.1.rc2Windows
Multiple Vulnerabilities are affected in BIND 9.7.0Windows
Vulnerabilities CVE-2009-4022,CVE-2010-3613,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.0.b1Windows
Vulnerabilities CVE-2009-4022,CVE-2010-3613,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.0.p1Windows
Vulnerabilities CVE-2009-4022,CVE-2010-3613,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.0.rc1Windows
Vulnerabilities CVE-2009-4022,CVE-2010-3613,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.0.rc2Windows
Multiple Vulnerabilities are affected in BIND 9.7.1Windows
Multiple Vulnerabilities are affected in BIND 9.7.1.p1Windows
Multiple Vulnerabilities are affected in BIND 9.7.2Windows
Multiple Vulnerabilities are affected in BIND 9.7.2.p1Windows
Vulnerabilities CVE-2010-3613,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.0.p2Windows
Vulnerabilities CVE-2010-3613,CVE-2011-0414,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.1.p2Windows
Vulnerabilities CVE-2010-3613,CVE-2011-0414,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.1.rc1Windows
Multiple Vulnerabilities are affected in BIND 9.7.2.p2Windows
Vulnerabilities CVE-2011-0414,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.2.p3Windows
Vulnerabilities CVE-2011-0414,CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.2.rc1Windows
Vulnerabilities CVE-2011-1907,CVE-2011-1910,CVE-2011-2465,CVE-2012-1033 are affected in BIND 9.8.0Windows
Vulnerabilities CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.3Windows
Vulnerabilities CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.7.3.b1Windows
Vulnerabilities CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.8.0.a1Windows
Vulnerabilities CVE-2011-1910,CVE-2012-1033 are affected in BIND 9.8.0.b1Windows
Vulnerabilities CVE-2011-1910,CVE-2011-2465,CVE-2012-1033 are affected in BIND 9.8.0.p1Windows
Vulnerabilities CVE-2011-2465,CVE-2012-1033 are affected in BIND 9.8.0.p2Windows
Vulnerabilities CVE-2011-2465,CVE-2012-1033 are affected in BIND 9.8.1.b1Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.7.3.p1Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.7.3.rc1Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.7.4Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.7.4.b1Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.8.0.p4Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.8.0.rc1Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.8.1Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.8.1.b2Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.8.1.b3Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.8.1.p1Windows
Vulnerabilities CVE-2012-1033 are affected in BIND 9.8.1.rc1Windows
Internet Domain Name Server (USN-1462-1) libdns81_9.8.1.dfsg.P1-4_i386.debLinux
Internet Domain Name Server (USN-1462-1) libdns81_9.8.1.dfsg.P1-4_amd64.debLinux
Internet Domain Name Server (USN-1462-1) libdns81_9.8.1.dfsg.P1-4ubuntu0.13_i386.debLinux
Internet Domain Name Server (USN-1462-1) libdns81_9.8.1.dfsg.P1-4ubuntu0.13_amd64.debLinux
CVE-2012-1033NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234