CVE-2006-2073: Medium severity isc bind vulnerability
Published Apr 27, 2006
·Updated
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
Affected Software
13 affected components
ISC BIND=9.0
ISC BIND=9.0.1
ISC BIND=9.1
ISC BIND=9.1.1
ISC BIND=9.1.2
ISC BIND=9.1.3
ISC BIND=9.2.0
ISC BIND=9.2.1
ISC BIND=9.2.2
ISC BIND=9.2.3
ISC BIND=9.3
ISC BIND=9.3.1
ISC BIND=9.3.2
Remediation
Patch Available
Event History
Apr 27, 2006
CVE Published
10:02 PM
Apr 28, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2073?
CVE-2006-2073 has been classified with a moderate severity due to its potential to cause denial of service.
2
How do I fix CVE-2006-2073?
To mitigate CVE-2006-2073, upgrade to a version of BIND that is not affected, such as BIND 9.3.3 or later.
3
What is the impact of CVE-2006-2073?
The impact of CVE-2006-2073 is a denial of service, which can interrupt DNS services.
4
In which versions of BIND is CVE-2006-2073 present?
CVE-2006-2073 affects BIND versions 9.0 through 9.3.2.
5
Who can exploit CVE-2006-2073?
CVE-2006-2073 can be exploited by remote attackers capable of sending crafted DNS messages.