PT-2010-5633 · Debian+4 · Libisccc50+9

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2010-3613

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux (affected versions not specified) ISC BIND versions 9.6.2 through 9.6.2-P3 ISC BIND versions 9.6-ESV through 9.6-ESV-R3 ISC BIND versions 9.7.x through 9.7.2-P3
Description The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including libisccc50, lwresd, libisccfg50, liblwres50, and libdns58, which can lead to disruption of data integrity and availability. These vulnerabilities can be exploited remotely. Additionally, a specific vulnerability in ISC BIND 9 allows remote attackers to cause a denial of service (daemon crash) by querying cached data that combines signed negative responses and corresponding RRSIG records.
Recommendations For ISC BIND 9.6.2, update to version 9.6.2-P3 or later. For ISC BIND 9.6-ESV, update to version 9.6-ESV-R3 or later. For ISC BIND 9.7.x, update to version 9.7.2-P3 or later. At the moment, there is no information about a newer version that contains a fix for the vulnerabilities in the Debian GNU/Linux packages.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01437
BDU:2015-01438
BDU:2015-01439
BDU:2015-01440
BDU:2015-01441
BDU:2015-01442
CVE-2010-3613
DSA-2130-1
HPSBUX02655
OPENSUSE-SU-2024:10467-1
RHSA-2010:0975
RHSA-2010:0976
RHSA-2010:1000
RHSA-2010_0975
RHSA-2010_0976
RHSA-2010_1000

Affected Products

Bind Server
Debian
Hp-Ux
Isc Bind
Red Hat
Libdns58
Libisccc50
Libisccfg50
Liblwres50
Lwresd