Vulnerability Name: | CVE-2006-4096 (CCN-28744) | ||||||||||||||||
Assigned: | 2006-09-05 | ||||||||||||||||
Published: | 2006-09-05 | ||||||||||||||||
Updated: | 2018-10-17 | ||||||||||||||||
Summary: | BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2006-4096 Source: CCN Type: Apple Security Update 2007-005 About Security Update 2007-005 Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=305530 Source: CCN Type: Apple Web site Apple security updates Source: CCN Type: NetBSD-SA2006-022 BIND recursive query and SIG query processing Source: APPLE Type: UNKNOWN APPLE-SA-2007-05-24 Source: HP Type: UNKNOWN HPSBOV03226 Source: CCN Type: SA21752 ISC BIND Denial of Service Vulnerabilities Source: SECUNIA Type: UNKNOWN 21752 Source: SECUNIA Type: UNKNOWN 21786 Source: SECUNIA Type: UNKNOWN 21790 Source: SECUNIA Type: UNKNOWN 21816 Source: SECUNIA Type: UNKNOWN 21818 Source: SECUNIA Type: UNKNOWN 21828 Source: SECUNIA Type: UNKNOWN 21835 Source: SECUNIA Type: UNKNOWN 21838 Source: SECUNIA Type: UNKNOWN 21912 Source: SECUNIA Type: UNKNOWN 21926 Source: SECUNIA Type: UNKNOWN 22298 Source: CCN Type: SA24950 HP Insight Management Agents SSL Vulnerabilities Source: SECUNIA Type: UNKNOWN 24950 Source: SECUNIA Type: UNKNOWN 25402 Source: FREEBSD Type: UNKNOWN FreeBSD-SA-06:20.bind Source: GENTOO Type: UNKNOWN GLSA-200609-11 Source: CCN Type: SECTRACK ID: 1016794 BIND Query Processing Bugs Let Remote Users Deny Service Source: SECTRACK Type: UNKNOWN 1016794 Source: SLACKWARE Type: UNKNOWN SSA:2006-257-01 Source: AIXAPAR Type: UNKNOWN IY89169 Source: AIXAPAR Type: UNKNOWN IY89178 Source: DEBIAN Type: DSA-1172 bind9 -- programming error Source: CCN Type: GLSA-200609-11 BIND: Denial of Service Source: CCN Type: Internet Software Consortium (ISC) Web site BIND (Berkeley Internet Name Domain) page Source: CCN Type: US-CERT VU#697164 BIND vulnerable to an INSIST failure via sending of multiple recursive queries Source: CERT-VN Type: Patch, US Government Resource VU#697164 Source: MANDRIVA Type: UNKNOWN MDKSA-2006:163 Source: CCN Type: NISCC Vulnerability Advisory 172003/NISCC/BIND9 Multiple DoS Vulnerabilities in the BIND 9 Software Source: MISC Type: Patch http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=en Source: SUSE Type: UNKNOWN SUSE-SR:2006:023 Source: SUSE Type: UNKNOWN SUSE-SR:2006:024 Source: OPENBSD Type: UNKNOWN [3.9] 20060908 010: SECURITY FIX: September 8, 2006 Source: CCN Type: OpenPKG-SA-2006.019 BIND Source: OPENPKG Type: UNKNOWN OpenPKG-SA-2006.019 Source: BUGTRAQ Type: UNKNOWN 20060908 rPSA-2006-0166-1 bind bind-utils Source: BID Type: UNKNOWN 19859 Source: CCN Type: BID-19859 ISC BIND Multiple Remote Denial of Service Vulnerabilities Source: CCN Type: TLSA-2006-27 bind denial of service attack Source: CCN Type: USN-343-1 bind9 vulnerabilities Source: UBUNTU Type: UNKNOWN USN-343-1 Source: DEBIAN Type: UNKNOWN DSA-1172 Source: VUPEN Type: UNKNOWN ADV-2006-3473 Source: VUPEN Type: UNKNOWN ADV-2006-3511 Source: VUPEN Type: UNKNOWN ADV-2007-1401 Source: VUPEN Type: UNKNOWN ADV-2007-1939 Source: XF Type: UNKNOWN bind-recursive-insist-dos(28744) Source: XF Type: UNKNOWN bind-recursive-insist-dos(28744) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-626 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9623 Source: SUSE Type: SUSE-SR:2006:024 SUSE Security Summary Report Source: HP Type: UNKNOWN SSRT071304 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |