Oval Definition:oval:org.mitre.oval:def:12245
Revision Date:2015-04-20Version:28
Title:HP-UX Running BIND, Remote Denial of Service (DoS)
Description:The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-0696
Platform(s):HP-UX 11
Product(s):
Definition Synopsis
  • Criteria meets HP Security Bulletin HPSBUX02451
  • HP-UX B.11.23
  • AND filesets tests
  • InternetSrvcs.INETSVCS-INETD is installed
  • OR InternetSrvcs.INETSVCS-RUN is installed
  • OR InternetSrvcs.INETSVCS2-RUN is installed
  • AND NOT Patch PHNE_40339 is installed
  • OR Criteria meets HP Security Bulletin HPSBUX02451
  • HP-UX B.11.11
  • AND BINDv920.INETSVCS-BIND version is less than B.11.11.01.014
  • OR Criteria meets HP Security Bulletin HPSBUX02451
  • HP-UX B.11.23
  • AND filesets tests
  • BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0
  • OR BindUpgrade.BIND2-UPGRADE version is less than C.9.3.2.7.0
  • OR Criteria meets HP Security Bulletin HPSBUX02451
  • HP-UX B.11.11
  • AND BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0
  • OR Criteria meets HP Security Bulletin HPSBUX02451
  • HP-UX B.11.31
  • AND filesets tests
  • NameService.BIND-AUX version is less than C.9.3.2.8.0
  • OR NameService.BIND-RUN version is less than C.9.3.2.8.0
  • BACK